STIGQter STIGQter: STIG Summary: Network Infrastructure Policy Security Technical Implementation Guide Version: 10 Release: 7 Benchmark Date: 24 Oct 2024:

An Intrusion Detection and Prevention System (IDPS) sensor must be deployed to monitor all Demilitarized Zone (DMZ) segments housing public servers.

DISA Rule

SV-251335r853642_rule

Vulnerability Number

V-251335

Group Title

NET-IDPS-016

Rule Version

NET-IDPS-016

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Place an IDPS sensor in the enclave to monitor public servers.

Check Contents

Review the DMZ topology and verify public servers are being monitored by an IDPS.

If an IDPS sensor is not deployed to monitor all DMZ segments housing public servers, this is a finding.

Vulnerability Number

V-251335

Documentable

False

Rule Version

NET-IDPS-016

Severity Override Guidance

Review the DMZ topology and verify public servers are being monitored by an IDPS.

If an IDPS sensor is not deployed to monitor all DMZ segments housing public servers, this is a finding.

Check Content Reference

M

Target Key

5444