Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000071-IDPS-000020 | SRG-NET-000071-IDPS-000020 | SRG-NET-000071-IDPS-000020_rule | Medium |
Description |
---|
DoDD 8100.2 requires ALL DoD networks use a wireless IDS to scan for unauthorized wireless devices. If sites do not maintain scan logs, it cannot be determined if IDS findings are isolated and harmless events or a more sustained, methodical attack on the system. |
STIG | Date |
---|---|
IDPS Security Requirements Guide (SRG) | 2012-03-08 |
Check Text ( C-43136_chk ) |
---|
Verify the site has saved its scan results for at least one year, viewing one of the older logs to validate the practice. If the site is not saving the logs/results or is saving them for less than one year, this is a finding. |
Fix Text (F-43136_fix) |
---|
Maintain WLAN scan results for at least one year. |