STIGQter STIGQter: STIG Summary: Intrusion Detection and Prevention Systems Security Requirements Guide Version: 3 Release: 4 Benchmark Date: 28 Oct 2025:

The IPS must restrict or block harmful or suspicious communications traffic between interconnected networks based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.

DISA Rule

SV-206865r1137717_rule

Vulnerability Number

V-206865

Group Title

SRG-NET-000019

Rule Version

SRG-NET-000019-IDPS-00019

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the IPS to enforce approved authorizations by restricting or blocking the flow of harmful or suspicious communications traffic for controlling the flow of information between interconnected networks.

Check Contents

If the device being reviews is an IDS, this is not applicable.

Verify the IPS enforces approved authorizations by restricting or blocking the flow of harmful or suspicious communications traffic for controlling the flow of information between interconnected networks.

If the IPS does not enforce approved authorizations by restricting or blocking the flow of harmful or suspicious communications traffic for controlling the flow of information between interconnected networks, this is a finding.

Vulnerability Number

V-206865

Documentable

False

Rule Version

SRG-NET-000019-IDPS-00019

Severity Override Guidance

If the device being reviews is an IDS, this is not applicable.

Verify the IPS enforces approved authorizations by restricting or blocking the flow of harmful or suspicious communications traffic for controlling the flow of information between interconnected networks.

If the IPS does not enforce approved authorizations by restricting or blocking the flow of harmful or suspicious communications traffic for controlling the flow of information between interconnected networks, this is a finding.

Check Content Reference

M

Target Key

2918