SV-251338r1007842_rule
V-251338
NET-IDPS-021
NET-IDPS-021
CAT II
10
Install an IDPS inline or passively, behind the enclave firewall to monitor all unencrypted traffic, inbound and outbound.
Review the network topology to ensure the enclave has the IDPS positioned to monitor all traffic to and from the enclave. Review any type of report that was recently produced from information provided by the sensor showing any recent alerts, an escalation activity and any type of log or configuration changes. This will show the sensor is being actively monitored and alerts are being acted upon. If the enclave's CNDSP requires continuous monitoring of the IDPS, the CNDSPs management team (e.g. sensor grid management team at DISA) will verify the operational status by providing information about the enclave's IDPS such as a network diagram, MOA, current alert information, or other information to validate its operational status.
Note: If the authorized Cybersecurity Service Provider (CSSP) can utilize security tools and services that ensures the network (can include perimeter connection and enclave) is monitored in a manner that would satisfy CJCSI 6510.01F, Enclosure A-5, Paragraph 8, an IDSP is not required to be part of the security solution.
If there is no IDPS positioned and enabled to monitor all ingress and egress traffic, this is a finding.
Exception: If the perimeter security for the enclave or B/C/P/S is provisioned via the JRSS, then this requirement is not applicable.
V-251338
False
NET-IDPS-021
Review the network topology to ensure the enclave has the IDPS positioned to monitor all traffic to and from the enclave. Review any type of report that was recently produced from information provided by the sensor showing any recent alerts, an escalation activity and any type of log or configuration changes. This will show the sensor is being actively monitored and alerts are being acted upon. If the enclave's CNDSP requires continuous monitoring of the IDPS, the CNDSPs management team (e.g. sensor grid management team at DISA) will verify the operational status by providing information about the enclave's IDPS such as a network diagram, MOA, current alert information, or other information to validate its operational status.
Note: If the authorized Cybersecurity Service Provider (CSSP) can utilize security tools and services that ensures the network (can include perimeter connection and enclave) is monitored in a manner that would satisfy CJCSI 6510.01F, Enclosure A-5, Paragraph 8, an IDSP is not required to be part of the security solution.
If there is no IDPS positioned and enabled to monitor all ingress and egress traffic, this is a finding.
Exception: If the perimeter security for the enclave or B/C/P/S is provisioned via the JRSS, then this requirement is not applicable.
M
5444