
Solutions
SigXOS supports security and network teams wherever technical requirements have to be checked and the configuration state has to be proven.
Configuration compliance
Check configurations repeatably
The challenge
Many devices, platforms and versions make consistent checks laborious. Manual one-off checks are error-prone and hard to repeat.
With SigXOS
- Apply defined security rules to the collected state
- A clear result per rule: deviation or passed
- Agentless, read-only collection via SSH
- F002Password obfuscation enabledDeviation
- F004SSH version 2 enforcedPassed
- F005Telnet disabled on VTY linesPassed
- F007Access list on VTY linesDeviation
2 deviations, 2 passed
Audit and evidence preparation
Prove findings instead of describing them
The challenge
A documented target state does not prove the current actual state. Audits need evidence that refers to the actual configuration.
With SigXOS
- Every finding points to the configuration
- Rule reference and time are documented
- Check report and audit trail for follow-up

Evidence
No 'access-class' configuration present in running-config
Recommendation
Restrict VTY access to trusted hosts with an access-class.
CIS-oriented configuration checks
Turn CIS recommendations into testable rules
The challenge
Benchmarks describe secure configurations. To help in operations, they have to be turned into concrete technical checks.
With SigXOS
- 22 CIS-oriented rules for Cisco IOS/IOS-XE in the prototype
- Severity per rule for prioritisation
- Rule quality and mappings are being checked in a validation matrix
- F001AAA authentication configuredCIS 1.1.1Critical
- F003Enable secret setCIS 1.4.1Critical
- F004SSH version 2 enforcedCIS 1.5.1High
- F006Session timeout on VTY linesCIS 1.5.4Medium
- F012Remote syslog server configuredCIS 2.4.1High
5 of 22 rules
Re-checks after changes
Prove it again after every change
The challenge
Configurations change all the time. A state checked once is no longer proven after the next change.
With SigXOS
- Re-check after changes
- Keep the history of results traceable
- Reproducible results for the same configuration state
- Check run before the changeDeviation
13
no service password-encryption - Check run after the changePassed
13
service password-encryption
Frameworks and standards
Reference frameworks for the check
Today the CIS Benchmarks form the rule basis. Mapping findings to further frameworks is planned.
CIS Benchmarks
22 CIS-oriented rules for Cisco IOS/IOS-XE in the prototype, each with CIS reference and severity.
NIS-2 / BSIG
Risk management duties for essential and important entities in Germany
PlannedBSI IT-Grundschutz
Modules and requirements of Germany’s BSI
PlannedISO/IEC 27001
Information security management system and Annex A controls
PlannedDORA
Digital operational resilience in the financial sector
PlannedPCI DSS
Security standard for card payments
PlannedNIST CSF 2.0
NIST Cybersecurity Framework
PlannedInternal policies
Your organisation’s own security requirements
Planned
SigXOS provides technical findings with evidence for selected requirements. Organisational measures, legal assessment and certification are outside its scope.
Who it is for
For teams that need to check and prove
Companies running their own networks
Security and network teams who need to check and prove configurations regularly.
Entities with NIS-2 obligations
Organisations under BSI supervision that want to document technical measures in a traceable way.
IT service providers and MSPs
Checks and evidence as a service for their own customers.
Planned
Is SigXOS a fit for your environment?
You need to check and prove configurations regularly? Let’s find out in 30 minutes whether a pilot makes sense: directly with Cisco IOS/IOS-XE, with other vendors on an individual timeline and plan.