[Verse 1]
Three device types guard our network core
Routers, switches, firewalls and more
But common rules apply across the board
DISA STIGs show us how to secure
Authentication's where we start the fight
TACACS RADIUS keep access tight
Local accounts when servers go down
Triple A framework keeps threats from town
[Chorus]
Authenticate Authorize Account for all
Management plane secured against the fall
Log everything with time stamps that align
Access control lists drawn by design
Protocol security router by router
Banners warning every network intruder
Firmware validated versions running clean
Network device STIGs keep systems lean
[Verse 2]
Management plane needs protection strong
SSH connections keep us safe from wrong
Never use Telnet sends passwords clear
SNMP version three keeps admin secure
Encrypted channels for every control
Web interfaces with TLS goals
Console access with proper authentication
Management VLAN isolation
[Chorus]
Authenticate Authorize Account for all
Management plane secured against the fall
Log everything with time stamps that align
Access control lists drawn by design
Protocol security router by router
Banners warning every network intruder
Firmware validated versions running clean
Network device STIGs keep systems lean
[Verse 3]
Logging tells the story of our network health
Syslog collectors gathering wealth
Central correlation needs synchronized time
NTP servers keep logs aligned
When incidents happen we need to see
Timeline of events chronologically
Without proper timestamps we're flying blind
Network forensics need time aligned
[Bridge]
Ingress filtering at the border gate
Egress filtering data we create
Anti spoofing stops the fake source lies
Access lists control who gets inside
OSPF BGP EIGRP too
Authentication keys for me and you
Routing protocols need security strong
Or attackers redirect where packets belong
[Verse 4]
Banner warnings greet each login screen
DoD approved messages keep networks clean
Legal notices tell users what's allowed
Unauthorized access isn't allowed
Firmware versions must be validated clean
Approved by DISA security team
Patches tested before deployment day
Vulnerability management leads the way
[Chorus]
Authenticate Authorize Account for all
Management plane secured against the fall
Log everything with time stamps that align
Access control lists drawn by design
Protocol security router by router
Banners warning every network intruder
Firmware validated versions running clean
Network device STIGs keep systems lean
[Outro]
Three device types one security goal
DISA STIGs keep networks under control
Router switch firewall working as one
Network security never done