Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-28942 | SRG-OS-000198 | SV-36933r1_rule | Medium |
Description |
---|
Intrusion-monitoring tools can accumulate a significant amount of sensitive data; examples could include user account information and application data not related to the intrusion monitoring application itself. Intrusion monitoring tools also obtain information that is critical to conducting forensic analysis on attacks that occur within the network. This data may be sensitive in nature. Information obtained by intrusion monitoring applications in the course of evaluating network and system security needs to be protected. While this is an operating system requirement, the data collected may be in different files or locations depending upon the IDS/IPS product being used. |
STIG | Date |
---|---|
Operating System Security Requirements Guide | 2011-12-28 |
Check Text ( None ) |
---|
None |
Fix Text (None) |
---|
None |