Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000115-IDPS-000075 | SRG-NET-000115-IDPS-000075 | SRG-NET-000115-IDPS-000075_rule | Medium |
Description |
---|
Logging specific events provides a means to investigate an attack, recognize resource utilization or capacity thresholds, or to simply identify an improperly configured IDPS. Locally developed sensor rules may be developed incorrectly and may not be configured for proper alerting. These rules implement organizationally defined security policies and are used to tailor the IDPS sensors to meet organizational requirements not provided by default vendor rules and updates (e.g., IAVMs). |
STIG | Date |
---|---|
IDPS Security Requirements Guide (SRG) | 2012-03-08 |
Check Text ( C-43203_chk ) |
---|
Check the logging settings on the sensors and the central management console. Verify the central logging system is receiving alert and reporting them according to company policies and procedures. If log alerts are not generated for locally developed sensor rules, this is a finding. |
Fix Text (F-43203_fix) |
---|
Use the management console to configure the sensors to generate log alerts for locally developed sensor rules. |