STIGQter STIGQter: STIG Summary: Intrusion Detection and Prevention Systems Security Requirements Guide Version: 3 Release: 4 Benchmark Date: 28 Oct 2025:

The IDPS must provide audit record generation capability for events where communication traffic is blocked or restricted based on policy filters, rules, signatures, and anomaly analysis.

DISA Rule

SV-206876r382900_rule

Vulnerability Number

V-206876

Group Title

SRG-NET-000113

Rule Version

SRG-NET-000113-IDPS-00082

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the IDPS to provide audit record generation capability for events where communication traffic is blocked or restricted based on policy filters, rules, signatures, and anomaly analysis algorithms.

Check Contents

Verify the configuration provides audit record generation capability for events where communication traffic is blocked or restricted based on policy filters, rules, signatures, and anomaly analysis algorithms.

If the IDPS does not provide audit record generation capability for events where communication traffic is blocked or restricted based on policy filters, rules, signatures, and anomaly analysis, this is a finding.

Vulnerability Number

V-206876

Documentable

False

Rule Version

SRG-NET-000113-IDPS-00082

Severity Override Guidance

Verify the configuration provides audit record generation capability for events where communication traffic is blocked or restricted based on policy filters, rules, signatures, and anomaly analysis algorithms.

If the IDPS does not provide audit record generation capability for events where communication traffic is blocked or restricted based on policy filters, rules, signatures, and anomaly analysis, this is a finding.

Check Content Reference

M

Target Key

2918