UCF STIG Viewer Logo

The IDPS must ensure detected unauthorized security-relevant configuration changes are tracked.


Overview

Finding ID Version Rule ID IA Controls Severity
V-34624 SRG-NET-000129-IDPS-00096 SV-45499r1_rule Medium
Description
Uncoordinated or incorrect configuration changes to network components can potentially lead to network outages and compromises. Centrally managing configuration changes for the IDPS can ensure they are done at the correct time and if necessary in synchronization with each other which can be vital for nodes that peer and require compatible configurations. Centralized configuration management also provides visibility and tracking of enterprise level activity promoting a sound configuration management procedure as well as an automatic mechanism to track detected unauthorized security-relevant configuration changes.
STIG Date
Intrusion Detection and Prevention Systems (IDPS) Security Requirements Guide 2012-11-19

Details

Check Text ( C-42848r1_chk )
Verify IDPS sensors log events detected by monitoring based on existing rules, signatures and other monitoring tools. Verify the IDPS logs access control and security policy violations occurring on the IDPS itself, to the application audit log or to the network syslog server.

If detected unauthorized security-relevant configuration changes are not logged in the sensor log, this is a finding. If access control and other security policy violations are not logged in the application audit log, this is a finding.
Fix Text (F-38896r1_fix)
Configure the IDPS to log events and anomalies detected during network monitoring.
Configure the IDPS application to log access control and other security policy violations in the application audit log.