UCF STIG Viewer Logo

The IDPS must employ automated mechanisms to assist in the tracking of security incidents.


Overview

Finding ID Version Rule ID IA Controls Severity
V-34687 SRG-NET-000170-IDPS-00127 SV-45567r1_rule Medium
Description
Despite the investment in perimeter defense technologies, enclaves are still faced with detecting, analyzing, and remediating network breaches and exploits that have made it past the firewall. An automated incident response infrastructure allows network operations to immediately react to incidents by identifying, analyzing, and mitigating any compromised network or the IDPS. Incident response teams can perform root cause analysis, determine how the exploit proliferated, identify all affected nodes, as well as contain and eliminate the threat. The IDPS assists in the tracking of security incidents by logging detected security events. The sensor log can be centralized and used as part of the organization's event analysis.
STIG Date
Intrusion Detection and Prevention Systems (IDPS) Security Requirements Guide 2012-11-19

Details

Check Text ( C-42918r1_chk )
View the sensor logs on each sensor. Also, view the central management console log and audit log function.

If the logs are not enabled, this is a finding.
Fix Text (F-38964r1_fix)
Enable the sensor, management console, and audit logs.