Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000224-IDPS-000179 | SRG-NET-000224-IDPS-000179 | SRG-NET-000224-IDPS-000179_rule | Medium |
Description |
---|
Public-facing servers enable access to information by clients outside of the enclave. These servers are subject to greater exposure to attacks. It is imperative that the integrity of the data is maintained to ensure the enclave does not provide false or erroneous information. The IDPS must provide the necessary protection to ensure availability and integrity of the data and to reduce or eliminate Denial-of-Service (DoS) attacks directed against the servers on the public-facing segment. A sensor must be installed to monitor and scan the publicly available segment (e.g., public DMZ). |
STIG | Date |
---|---|
IDPS Security Requirements Guide (SRG) | 2012-03-08 |
Check Text ( C-43323_chk ) |
---|
Examine the architecture diagrams. Verify a sensor is installed and configured to monitor and protect the public DMZ. If a sensor is not installed to protect the public DMZ subnet, this is a finding. |
Fix Text (F-43323_fix) |
---|
Install and configure a sensor to monitor the public DMZ subnet. |