UCF STIG Viewer Logo

The IDPS must employ automated mechanisms to assist in the tracking of security incidents.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000170-IDPS-000158 SRG-NET-000170-IDPS-000158 SRG-NET-000170-IDPS-000158_rule Medium
Description
Despite the investment in perimeter defense technologies, enclaves are still faced with detecting, analyzing, and remediating network breaches and exploits that have made it past the firewall. An automated incident response infrastructure allows network operations to immediately react to incidents by identifying, analyzing, and mitigating any compromised network or the IDPS. Incident response teams can perform root cause analysis, determine how the exploit proliferated, identify all affected nodes, as well as, contain and eliminate the threat.
STIG Date
IDPS Security Requirements Guide (SRG) 2012-03-08

Details

Check Text ( C-43298_chk )
View the sensor logs and the central management log.

If the logs are not enabled, this is a finding.
Fix Text (F-43298_fix)
Enable the sensor logs to assist in the tracking of security incidents.