| Checked | Name | Title |
|---|
| ☐ | SV-206864r1137714_rule | The IPS must enforce approved authorizations by restricting or blocking the flow of harmful or suspicious communications traffic within the network. |
| ☐ | SV-206865r1137717_rule | The IPS must restrict or block harmful or suspicious communications traffic between interconnected networks based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic. |
| ☐ | SV-206866r1137718_rule | The IDPS must immediately use updates made to policy filters, rules, signatures, and anomaly analysis algorithms for traffic detection and prevention functions. |
| ☐ | SV-206867r382855_rule | The IDPS must produce audit records containing sufficient information to establish what type of event occurred, including, at a minimum, event descriptions, policy filter, rule or signature invoked, port, protocol, and criticality level/alert code or description. |
| ☐ | SV-206868r382858_rule | The IDPS must produce audit records containing information to establish when (date and time) the events occurred. |
| ☐ | SV-206869r382861_rule | The IDPS must produce audit records containing information to establish where the event was detected, including, at a minimum, network segment, destination address, and IDPS component which detected the event. |
| ☐ | SV-206870r382864_rule | The IDPS must produce audit records containing information to establish the source of the event, including, at a minimum, originating source address. |
| ☐ | SV-206871r382867_rule | The IDPS must produce audit records containing information to establish the outcome of events associated with detected harmful or potentially harmful traffic, including, at a minimum, capturing all associated communications traffic. |
| ☐ | SV-206874r382879_rule | The IDPS must provide log information in a format that can be extracted and used by centralized analysis tools. |
| ☐ | SV-206875r382900_rule | The IDPS must provide audit record generation capability for detection events based on implementation of policy filters, rules, signatures, and anomaly analysis. |
| ☐ | SV-206876r382900_rule | The IDPS must provide audit record generation capability for events where communication traffic is blocked or restricted based on policy filters, rules, signatures, and anomaly analysis. |
| ☐ | SV-206877r382900_rule | The IDPS must provide audit record generation with a configurable severity and escalation level capability. |
| ☐ | SV-206878r382903_rule | The IDPS must be configured to remove or disable non-essential capabilities which are not required for operation or not related to IDPS functionality (e.g., DNS, email client or server, FTP server, or web server). |
| ☐ | SV-206879r382903_rule | The IDPS must be configured to remove or disable non-essential features, functions, and services of the IDPS application. |
| ☐ | SV-206880r552959_rule | The IDPS must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments. |
| ☐ | SV-206881r1140706_rule | The IPS must block outbound traffic containing known and unknown denial-of-service (DoS) attacks by ensuring that security policies, signatures, rules, and anomaly detection techniques are applied to outbound communications traffic. |
| ☐ | SV-206882r383101_rule | The IDPS must detect, at a minimum, mobile code that is unsigned or exhibiting unusual behavior, has not undergone a risk assessment, or is prohibited for use based on a risk assessment. |
| ☐ | SV-206883r1137731_rule | The IPS must block any prohibited mobile code at the enclave boundary when it is detected. |
| ☐ | SV-206884r383119_rule | The IDPS must fail to a secure state which maintains access control mechanisms when the IDPS hardware, software, or firmware fails on initialization/shutdown or experiences a sudden abort during normal operation. |
| ☐ | SV-206885r383122_rule | In the event of a failure of the IDPS function, the IDPS must save diagnostic information, log system messages, and load the most current security policies, rules, and signatures when restarted. |
| ☐ | SV-206887r982258_rule | The IDPS must automatically update malicious code protection mechanisms as new releases are available in accordance with organizational configuration management procedures. |
| ☐ | SV-206888r982259_rule | The IDPS must perform real-time monitoring of files from external sources at network entry/exit points. |
| ☐ | SV-206889r1137734_rule | The IPS must block malicious code. |
| ☐ | SV-206890r1137737_rule | The IPS must quarantine or block malicious code. |
| ☐ | SV-206891r383131_rule | The IDPS must send an immediate (within seconds) alert to, at a minimum, the system administrator when malicious code is detected. |
| ☐ | SV-206892r982260_rule | The IDPS must automatically update malicious code protection mechanisms as new releases are available in accordance with organizational configuration management policy. |
| ☐ | SV-206893r1137740_rule | The IPS must block outbound Internet Control Message Protocol (ICMP) Destination Unreachable, Redirect, and Address Mask reply messages. |
| ☐ | SV-206894r1137743_rule | The IPS must block malicious Internet Control Message Protocol (ICMP) packets by properly configuring ICMP signatures and rules. |
| ☐ | SV-206895r1137746_rule | To protect against unauthorized data mining, the IPS must prevent code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields. |
| ☐ | SV-206896r1137749_rule | To protect against unauthorized data mining, the IPS must prevent code injection attacks launched against application objects including, at a minimum, application URLs and application code. |
| ☐ | SV-206897r1137752_rule | To protect against unauthorized data mining, the IPS must prevent SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields. |
| ☐ | SV-206898r856536_rule | To protect against unauthorized data mining, the IDPS must detect code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields. |
| ☐ | SV-206899r856537_rule | To protect against unauthorized data mining, the IDPS must detect code injection attacks launched against application objects including, at a minimum, application URLs and application code. |
| ☐ | SV-206900r856538_rule | To protect against unauthorized data mining, the IDPS must detect SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields. |
| ☐ | SV-206902r856540_rule | The IDPS must off-load log records to a centralized log server. |
| ☐ | SV-206903r856541_rule | The IDPS must provide an alert to, at a minimum, the system administrator and ISSO when any audit failure events occur. |
| ☐ | SV-206904r856542_rule | The IDPS must assign a critical severity level to all audit processing failures. |
| ☐ | SV-206905r1137755_rule | The IPS must protect against or limit the effects of known and unknown types of denial-of-service (DoS) attacks by employing rate-based attack prevention behavior analysis. |
| ☐ | SV-206906r1137758_rule | The IPS must protect against or limit the effects of known and unknown types of denial-of-service (DoS) attacks by employing anomaly-based attack detection. |
| ☐ | SV-206907r1137761_rule | The IPS must protect against or limit the effects of known types of denial-of-service (DoS) attacks by employing signatures. |
| ☐ | SV-206909r856546_rule | IDPS components, including sensors, event databases, and management consoles must integrate with a network-wide monitoring capability. |
| ☐ | SV-206910r856547_rule | The IDPS must detect network services that have not been authorized or approved by the ISSO or ISSM, at a minimum. |
| ☐ | SV-206911r856548_rule | The IDPS must generate a log record when unauthorized network services are detected. |
| ☐ | SV-206912r856549_rule | The IDPS must generate an alert to the ISSM and ISSO, at a minimum, when unauthorized network services are detected. |
| ☐ | SV-206913r856550_rule | The IDPS must continuously monitor inbound communications traffic for unusual/unauthorized activities or conditions. |
| ☐ | SV-206914r856551_rule | The IDPS must continuously monitor outbound communications traffic for unusual/unauthorized activities or conditions. |
| ☐ | SV-206915r1107640_rule | The IDPS must send an alert to, at a minimum, the information system security manager (ISSM) and information system security officer (ISSO) when intrusion detection events are detected which indicate a compromise or potential for compromise. |
| ☐ | SV-206916r971533_rule | The IDPS must send an alert to, at a minimum, the ISSM and ISSO when threats identified by authoritative sources (e.g., IAVMs or CTOs) are detected which indicate a compromise or potential for compromise. |
| ☐ | SV-206917r971533_rule | The IDPS must generate an alert to, at a minimum, the ISSM and ISSO when root level intrusion events which provide unauthorized privileged access are detected. |
| ☐ | SV-206918r971533_rule | The IDPS must send an alert to, at a minimum, the ISSM and ISSO when user level intrusions which provide non-privileged access are detected. |
| ☐ | SV-206919r971533_rule | The IDPS must send an alert to, at a minimum, the ISSM and ISSO when denial of service incidents are detected. |
| ☐ | SV-206920r971533_rule | The IDPS must generate an alert to, at a minimum, the ISSM and ISSO when new active propagation of malware infecting DoD systems or malicious code adversely affecting the operations and/or security
of DoD systems is detected. |
| ☐ | SV-206921r383821_rule | The IDPS must, for fragmented packets, either block the packets or properly reassemble the packets before inspecting and forwarding. |
| ☐ | SV-206922r856558_rule | The IDPS must off-load log records to a centralized log server in real-time. |
| ☐ | SV-206923r385561_rule | The IDPS must be configured in accordance with the security configuration settings based on DoD security policy and technology-specific security best practices. |
| ☐ | SV-263663r991597_rule | The IDPS must employ organization-defined controls by type of denial-of-service (DoS) to achieve the DoS objective. |
| ☐ | SV-263664r1137722_rule | The IDPS must implement physically or logically separate subnetworks to isolate organization-defined critical system components and functions. |
| ☐ | SV-263665r991599_rule | The IDPS must establish organization-defined alternate communications paths for system operations organizational command and control. |
| ☐ | SV-278978r1137721_rule | The IDPS must use organization-defined security attributes associated with organization-defined information, source, and destination objects to enforce organization-defined information flow control policies as a basis for flow control decisions. |
| ☐ | SV-278979r1137725_rule | The IDPS must provide visibility into network traffic at external and key internal system interfaces to optimize the effectiveness of monitoring devices. |