An Intrusion Detection and Prevention System (IDPS) sensor must be deployed to monitor network segments that house network security management servers.
DISA Rule
SV-251337r853644_rule
Vulnerability Number
V-251337
Group Title
NET-IDPS-019
Rule Version
NET-IDPS-019
Severity
CAT II
CCI(s)
- CCI-001097 - Monitor and control communications at the external managed interfaces to the system and at key managed interfaces within the system.
- CCI-001255 - Invoke internal monitoring capabilities or deploy monitoring devices strategically within the system to collect organization-determined essential information.
- CCI-002668 - Defines the interior points within the system where outbound communications will be analyzed to discover anomalies.
Weight
10
Fix Recommendation
Install an IDPS to monitor and protect the Management Network (management subnet or OOB network).
Check Contents
Review the management network topology and verify network security management servers are being monitored by an IDPS.
If an IDPS sensor is not deployed to monitor all segments housing network security management servers, this is a finding.
Vulnerability Number
V-251337
Documentable
False
Rule Version
NET-IDPS-019
Severity Override Guidance
Review the management network topology and verify network security management servers are being monitored by an IDPS.
If an IDPS sensor is not deployed to monitor all segments housing network security management servers, this is a finding.
Check Content Reference
M
Target Key
5444