Rule ID
SV-251346r805993_rule
Version
V10R7
CCIs
CCI-000366
IDPS data needs to be backed up to ensure preservation in the case a loss of data due to hardware failure or malicious activity.
Interview the SA to determine the IDPS backup procedures as well as have SA display the backup files saved on the file server. If the IDPS data is not backed up on a weekly basis, this is a finding.
The organization must establish weekly backup procedures for the network IDS/IPS data.