An Intrusion Detection and Prevention System (IDPS) sensor must be deployed to monitor all Demilitarized Zone (DMZ) segments housing public servers.
DISA Rule
SV-251335r853642_rule
Vulnerability Number
V-251335
Group Title
NET-IDPS-016
Rule Version
NET-IDPS-016
Severity
CAT II
CCI(s)
- CCI-001097 - Monitor and control communications at the external managed interfaces to the system and at key managed interfaces within the system.
- CCI-001255 - Invoke internal monitoring capabilities or deploy monitoring devices strategically within the system to collect organization-determined essential information.
- CCI-002668 - Defines the interior points within the system where outbound communications will be analyzed to discover anomalies.
Weight
10
Fix Recommendation
Place an IDPS sensor in the enclave to monitor public servers.
Check Contents
Review the DMZ topology and verify public servers are being monitored by an IDPS.
If an IDPS sensor is not deployed to monitor all DMZ segments housing public servers, this is a finding.
Vulnerability Number
V-251335
Documentable
False
Rule Version
NET-IDPS-016
Severity Override Guidance
Review the DMZ topology and verify public servers are being monitored by an IDPS.
If an IDPS sensor is not deployed to monitor all DMZ segments housing public servers, this is a finding.
Check Content Reference
M
Target Key
5444