UCF STIG Viewer Logo

The IDPS must generate log alerts for locally developed sensor rules.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000115-IDPS-000075 SRG-NET-000115-IDPS-000075 SRG-NET-000115-IDPS-000075_rule Medium
Description
Logging specific events provides a means to investigate an attack, recognize resource utilization or capacity thresholds, or to simply identify an improperly configured IDPS. Locally developed sensor rules may be developed incorrectly and may not be configured for proper alerting. These rules implement organizationally defined security policies and are used to tailor the IDPS sensors to meet organizational requirements not provided by default vendor rules and updates (e.g., IAVMs).
STIG Date
IDPS Security Requirements Guide (SRG) 2012-03-08

Details

Check Text ( C-43203_chk )
Check the logging settings on the sensors and the central management console.
Verify the central logging system is receiving alert and reporting them according to company policies and procedures.

If log alerts are not generated for locally developed sensor rules, this is a finding.
Fix Text (F-43203_fix)
Use the management console to configure the sensors to generate log alerts for locally developed sensor rules.