STIGQter STIGQter: STIG Summary:

Intrusion Detection and Prevention Systems Security Requirements Guide

Version: 3

Release: 4 Benchmark Date: 28 Oct 2025

CheckedNameTitle
SV-206864r1137714_ruleThe IPS must enforce approved authorizations by restricting or blocking the flow of harmful or suspicious communications traffic within the network.
SV-206865r1137717_ruleThe IPS must restrict or block harmful or suspicious communications traffic between interconnected networks based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.
SV-206866r1137718_ruleThe IDPS must immediately use updates made to policy filters, rules, signatures, and anomaly analysis algorithms for traffic detection and prevention functions.
SV-206867r382855_ruleThe IDPS must produce audit records containing sufficient information to establish what type of event occurred, including, at a minimum, event descriptions, policy filter, rule or signature invoked, port, protocol, and criticality level/alert code or description.
SV-206868r382858_ruleThe IDPS must produce audit records containing information to establish when (date and time) the events occurred.
SV-206869r382861_ruleThe IDPS must produce audit records containing information to establish where the event was detected, including, at a minimum, network segment, destination address, and IDPS component which detected the event.
SV-206870r382864_ruleThe IDPS must produce audit records containing information to establish the source of the event, including, at a minimum, originating source address.
SV-206871r382867_ruleThe IDPS must produce audit records containing information to establish the outcome of events associated with detected harmful or potentially harmful traffic, including, at a minimum, capturing all associated communications traffic.
SV-206874r382879_ruleThe IDPS must provide log information in a format that can be extracted and used by centralized analysis tools.
SV-206875r382900_ruleThe IDPS must provide audit record generation capability for detection events based on implementation of policy filters, rules, signatures, and anomaly analysis.
SV-206876r382900_ruleThe IDPS must provide audit record generation capability for events where communication traffic is blocked or restricted based on policy filters, rules, signatures, and anomaly analysis.
SV-206877r382900_ruleThe IDPS must provide audit record generation with a configurable severity and escalation level capability.
SV-206878r382903_ruleThe IDPS must be configured to remove or disable non-essential capabilities which are not required for operation or not related to IDPS functionality (e.g., DNS, email client or server, FTP server, or web server).
SV-206879r382903_ruleThe IDPS must be configured to remove or disable non-essential features, functions, and services of the IDPS application.
SV-206880r552959_ruleThe IDPS must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
SV-206881r1140706_ruleThe IPS must block outbound traffic containing known and unknown denial-of-service (DoS) attacks by ensuring that security policies, signatures, rules, and anomaly detection techniques are applied to outbound communications traffic.
SV-206882r383101_ruleThe IDPS must detect, at a minimum, mobile code that is unsigned or exhibiting unusual behavior, has not undergone a risk assessment, or is prohibited for use based on a risk assessment.
SV-206883r1137731_ruleThe IPS must block any prohibited mobile code at the enclave boundary when it is detected.
SV-206884r383119_ruleThe IDPS must fail to a secure state which maintains access control mechanisms when the IDPS hardware, software, or firmware fails on initialization/shutdown or experiences a sudden abort during normal operation.
SV-206885r383122_ruleIn the event of a failure of the IDPS function, the IDPS must save diagnostic information, log system messages, and load the most current security policies, rules, and signatures when restarted.
SV-206887r982258_ruleThe IDPS must automatically update malicious code protection mechanisms as new releases are available in accordance with organizational configuration management procedures.
SV-206888r982259_ruleThe IDPS must perform real-time monitoring of files from external sources at network entry/exit points.
SV-206889r1137734_ruleThe IPS must block malicious code.
SV-206890r1137737_ruleThe IPS must quarantine or block malicious code.
SV-206891r383131_ruleThe IDPS must send an immediate (within seconds) alert to, at a minimum, the system administrator when malicious code is detected.
SV-206892r982260_ruleThe IDPS must automatically update malicious code protection mechanisms as new releases are available in accordance with organizational configuration management policy.
SV-206893r1137740_ruleThe IPS must block outbound Internet Control Message Protocol (ICMP) Destination Unreachable, Redirect, and Address Mask reply messages.
SV-206894r1137743_ruleThe IPS must block malicious Internet Control Message Protocol (ICMP) packets by properly configuring ICMP signatures and rules.
SV-206895r1137746_ruleTo protect against unauthorized data mining, the IPS must prevent code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.
SV-206896r1137749_ruleTo protect against unauthorized data mining, the IPS must prevent code injection attacks launched against application objects including, at a minimum, application URLs and application code.
SV-206897r1137752_ruleTo protect against unauthorized data mining, the IPS must prevent SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.
SV-206898r856536_ruleTo protect against unauthorized data mining, the IDPS must detect code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.
SV-206899r856537_ruleTo protect against unauthorized data mining, the IDPS must detect code injection attacks launched against application objects including, at a minimum, application URLs and application code.
SV-206900r856538_ruleTo protect against unauthorized data mining, the IDPS must detect SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.
SV-206902r856540_ruleThe IDPS must off-load log records to a centralized log server.
SV-206903r856541_ruleThe IDPS must provide an alert to, at a minimum, the system administrator and ISSO when any audit failure events occur.
SV-206904r856542_ruleThe IDPS must assign a critical severity level to all audit processing failures.
SV-206905r1137755_ruleThe IPS must protect against or limit the effects of known and unknown types of denial-of-service (DoS) attacks by employing rate-based attack prevention behavior analysis.
SV-206906r1137758_ruleThe IPS must protect against or limit the effects of known and unknown types of denial-of-service (DoS) attacks by employing anomaly-based attack detection.
SV-206907r1137761_ruleThe IPS must protect against or limit the effects of known types of denial-of-service (DoS) attacks by employing signatures.
SV-206909r856546_ruleIDPS components, including sensors, event databases, and management consoles must integrate with a network-wide monitoring capability.
SV-206910r856547_ruleThe IDPS must detect network services that have not been authorized or approved by the ISSO or ISSM, at a minimum.
SV-206911r856548_ruleThe IDPS must generate a log record when unauthorized network services are detected.
SV-206912r856549_ruleThe IDPS must generate an alert to the ISSM and ISSO, at a minimum, when unauthorized network services are detected.
SV-206913r856550_ruleThe IDPS must continuously monitor inbound communications traffic for unusual/unauthorized activities or conditions.
SV-206914r856551_ruleThe IDPS must continuously monitor outbound communications traffic for unusual/unauthorized activities or conditions.
SV-206915r1107640_ruleThe IDPS must send an alert to, at a minimum, the information system security manager (ISSM) and information system security officer (ISSO) when intrusion detection events are detected which indicate a compromise or potential for compromise.
SV-206916r971533_ruleThe IDPS must send an alert to, at a minimum, the ISSM and ISSO when threats identified by authoritative sources (e.g., IAVMs or CTOs) are detected which indicate a compromise or potential for compromise.
SV-206917r971533_ruleThe IDPS must generate an alert to, at a minimum, the ISSM and ISSO when root level intrusion events which provide unauthorized privileged access are detected.
SV-206918r971533_ruleThe IDPS must send an alert to, at a minimum, the ISSM and ISSO when user level intrusions which provide non-privileged access are detected.
SV-206919r971533_ruleThe IDPS must send an alert to, at a minimum, the ISSM and ISSO when denial of service incidents are detected.
SV-206920r971533_ruleThe IDPS must generate an alert to, at a minimum, the ISSM and ISSO when new active propagation of malware infecting DoD systems or malicious code adversely affecting the operations and/or security of DoD systems is detected.
SV-206921r383821_ruleThe IDPS must, for fragmented packets, either block the packets or properly reassemble the packets before inspecting and forwarding.
SV-206922r856558_ruleThe IDPS must off-load log records to a centralized log server in real-time.
SV-206923r385561_ruleThe IDPS must be configured in accordance with the security configuration settings based on DoD security policy and technology-specific security best practices.
SV-263663r991597_ruleThe IDPS must employ organization-defined controls by type of denial-of-service (DoS) to achieve the DoS objective.
SV-263664r1137722_ruleThe IDPS must implement physically or logically separate subnetworks to isolate organization-defined critical system components and functions.
SV-263665r991599_ruleThe IDPS must establish organization-defined alternate communications paths for system operations organizational command and control.
SV-278978r1137721_ruleThe IDPS must use organization-defined security attributes associated with organization-defined information, source, and destination objects to enforce organization-defined information flow control policies as a basis for flow control decisions.
SV-278979r1137725_ruleThe IDPS must provide visibility into network traffic at external and key internal system interfaces to optimize the effectiveness of monitoring devices.