UCF STIG Viewer Logo

The IDPS must employ automated mechanisms to detect the addition of unauthorized components or devices.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000132-IDPS-NA SRG-NET-000132-IDPS-NA SRG-NET-000132-IDPS-NA_rule Medium
Description
Centrally managing configuration changes for all network devices can ensure they are done at the correct time and if necessary in synchronization with each other which can be vital for nodes that peer and require compatible configurations. Centralized configuration management also provides visibility and tracking of enterprise level activity promoting a sound configuration management procedure as well as an automatic mechanism to track the status of applicable vulnerabilities. Keeping an up-to-date inventory of all network devices and their components provides the framework for the implementation of a comprehensive configuration and problem management system. An inventory of components and their features provides a mechanism for tracking vulnerabilities of affected products which can be used for automated patch management and upgrades. Monitoring may be accomplished on an ongoing basis or by the periodic scanning. Automated mechanisms can be implemented within the network. Centrally managing configuration of network devices and tracking vulnerable is not the role of an IDPS.
STIG Date
IDPS Security Requirements Guide (SRG) 2012-03-08

Details

Check Text ( C-43257_chk )
This requirement does not apply to IDPS.
Fix Text (F-43257_fix)
Not applicable for IDPS. No fix required.