UCF STIG Viewer Logo

The IDPS must ensure that detected unauthorized security-relevant configuration changes are tracked.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000129-IDPS-000121 SRG-NET-000129-IDPS-000121 SRG-NET-000129-IDPS-000121_rule Medium
Description
Uncoordinated or incorrect configuration changes to network components can potentially lead to network outages and possibly compromises. Centrally managing configuration changes for the IDPS can ensure they are done at the correct time and if necessary in synchronization with each other which can be vital for nodes that peer and require compatible configurations. Centralized configuration management also provides visibility and tracking of enterprise level activity promoting a sound configuration management procedure as well as an automatic mechanism to track detected unauthorized security-relevant configuration changes.
STIG Date
IDPS Security Requirements Guide (SRG) 2012-03-08

Details

Check Text ( C-43252_chk )
Verify IDPS sensors log events detected by scans based on existing rules, signatures and other scanning tools. Verify the IDPS logs access control and security policy violations occurring on the IDPS itself, to the application audit log or to the network syslog server.

If detected unauthorized security-relevant configuration changes are not logged in the sensor log, this is a finding. If access control and other security policy violations are not logged in the application audit log, this is a finding.
Fix Text (F-43252_fix)
Configure the IDPS to log events and anomalies detected during network monitoring and scanning.
Configure the IDPS application to log access control and other security policy violations in the application audit log.