STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 2 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to STIGs

Intrusion Detection and Prevention Systems (IDPS) Security Requirements Guide

Archived

Version

V2R6

Release Date

Jul 24, 2020

SCAP Benchmark ID

S-30307e26f29c84e18e5134e4d663fc579e81f5ce

Total Checks

59

Tags

other
CAT I: 0CAT II: 59CAT III: 0

The IDPS Security Requirements Guide (SRG) is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements are derived from the NIST 800-53 and related documents. Comments or proposed revisions to this document should be sent via e-mail to the following address: disa.letterkenny.FSO.mbx.stig-customer-support-mailbox@mail.mil.

Export CKLExport CSVExport JSON

Checks (59)

V-34484MEDIUMThe IDPS must enforce approved authorizations by restricting or blocking the flow of harmful or suspicious communications traffic within the network as defined in the PPSM CAL and vulnerability assessments.V-34485MEDIUMThe IDPS must restrict or block harmful or suspicious communications traffic between interconnected networks based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.V-34540MEDIUMThe IDPS must produce audit records containing sufficient information to establish what type of event occurred, including, at a minimum, event descriptions, policy filter, rule or signature invoked, port, protocol, and criticality level/alert code or description.V-34541MEDIUMThe IDPS must produce audit records containing information to establish when (date and time) the events occurred.V-34542MEDIUMThe IDPS must produce audit records containing information to establish where the event was detected, including, at a minimum, network segment, destination address, and IDPS component which detected the event.V-34543MEDIUMThe IDPS must produce audit records containing information to establish the source of the event, including, at a minimum, originating source address.V-34544MEDIUMThe IDPS must produce audit records containing information to establish the outcome of events associated with detected harmful or potentially harmful traffic, including, at a minimum, capturing all associated communications traffic.V-34555MEDIUMIn the event of a logging failure caused by the lack of audit record storage capacity, the IDPS must continue generating and storing audit records if possible, overwriting the oldest audit records in a first-in-first-out manner.V-34594MEDIUMThe IDPS must provide audit record generation capability for events where communication traffic is blocked or restricted based on policy filters, rules, signatures, and anomaly analysis.V-34625MEDIUMThe IDPS must be configured to remove or disable non-essential features, functions, and services of the IDPS application.V-34707MEDIUMThe IDPS must block outbound traffic containing known and unknown DoS attacks by ensuring that security policies, signatures, rules, and anomaly detection techniques are applied to outbound communications traffic.V-34743MEDIUMThe IDPS must block any prohibited mobile code at the enclave boundary when it is detected.V-34749MEDIUMThe IDPS must fail to a secure state which maintains access control mechanisms when the IDPS hardware, software, or firmware fails on initialization/shutdown or experiences a sudden abort during normal operation. V-34750MEDIUMIn the event of a failure of the IDPS function, the IDPS must save diagnostic information, log system messages, and load the most current security policies, rules, and signatures when restarted.V-34759MEDIUMThe IDPS must verify the integrity of updates obtained directly from the vendor.V-34762MEDIUMThe IDPS must block malicious code.V-34788MEDIUMThe IDPS must block outbound ICMP Destination Unreachable, Redirect, and Address Mask reply messages.V-55317MEDIUMThe IDPS must immediately use updates made to policy filters, rules, signatures, and anomaly analysis algorithms for traffic detection and prevention functions.V-55319MEDIUMThe IDPS must provide audit record generation capability for detection events based on implementation of policy filters, rules, signatures, and anomaly analysis.V-55321MEDIUMThe IDPS must provide audit record generation with a configurable severity and escalation level capability.V-55323MEDIUMIDPS must support centralized management and configuration of the content captured in audit records generated by all IDPS components.V-55325MEDIUMThe IDPS must off-load log records to a centralized log server.V-55327MEDIUMThe IDPS must off-load log records to a centralized log server in real-time.V-55329MEDIUMThe IDPS must assign a critical severity level to all audit processing failures.V-55331MEDIUMThe IDPS must provide an alert to, at a minimum, the system administrator and ISSO when any audit failure events occur.V-55333MEDIUMIn the event of a logging failure, caused by loss of communications with the central logging server, the IDPS must queue audit records locally until communication is restored or until the audit records are retrieved manually or using automated synchronization tools.V-55335MEDIUMThe IDPS must provide log information in a format that can be extracted and used by centralized analysis tools.V-55337MEDIUMThe IDPS must be configured in accordance with the security configuration settings based on DoD security policy and technology-specific security best practices.V-55339MEDIUMThe IDPS must be configured to remove or disable non-essential capabilities which are not required for operation or not related to IDPS functionality (e.g., DNS, email client or server, FTP server, or web server).V-55341MEDIUMThe IDPS must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.V-55343MEDIUMThe IDPS must detect, at a minimum, mobile code that is unsigned or exhibiting unusual behavior, has not undergone a risk assessment, or is prohibited for use based on a risk assessment.V-55345MEDIUMThe IDPS must protect against or limit the effects of known and unknown types of Denial of Service (DoS) attacks by employing rate-based attack prevention behavior analysis.V-55347MEDIUMThe IDPS must protect against or limit the effects of known and unknown types of Denial of Service (DoS) attacks by employing anomaly-based attack detection.V-55349MEDIUMThe IDPS must protect against or limit the effects of known types of Denial of Service (DoS) attacks by employing signatures.V-55351MEDIUMThe IDPS must, for fragmented packets, either block the packets or properly reassemble the packets before inspecting and forwarding.V-55355MEDIUMThe IDPS must block malicious ICMP packets by properly configuring ICMP signatures and rules.V-55357MEDIUMThe IDPS must install updates for application software files, signature definitions, detection heuristics, and vendor-provided rules when new releases are available in accordance with organizational configuration management policy and procedures.V-55359MEDIUMThe IDPS must perform real-time monitoring of files from external sources at network entry/exit points.V-55361MEDIUMThe IDPS must quarantine and/or delete malicious code.V-55363MEDIUMThe IDPS must send an immediate (within seconds) alert to, at a minimum, the system administrator when malicious code is detected.V-55365MEDIUMIDPS components, including sensors, event databases, and management consoles must integrate with a network-wide monitoring capability.V-55375MEDIUMThe IDPS must detect network services that have not been authorized or approved by the ISSO or ISSM, at a minimum.V-55377MEDIUMThe IDPS must generate a log record when unauthorized network services are detected.V-55379MEDIUMThe IDPS must generate an alert to the ISSM and ISSO, at a minimum, when unauthorized network services are detected.V-55381MEDIUMThe IDPS must continuously monitor inbound communications traffic for unusual/unauthorized activities or conditions.V-55383MEDIUMThe IDPS must continuously monitor outbound communications traffic for unusual/unauthorized activities or conditions.V-55385MEDIUMThe IDSP must send an alert to, at a minimum, the ISSM and ISSO when intrusion detection events are detected which indicate a compromise or potential for compromise.V-55387MEDIUMThe IDPS must send an alert to, at a minimum, the ISSM and ISSO when threats identified by authoritative sources (e.g., IAVMs or CTOs) are detected which indicate a compromise or potential for compromise.V-55389MEDIUMThe IDPS must generate an alert to, at a minimum, the ISSM and ISSO when root level intrusion events which provide unauthorized privileged access are detected.V-55391MEDIUMThe IDPS must send an alert to, at a minimum, the ISSM and ISSO when user level intrusions which provide non-privileged access are detected.V-55393MEDIUMThe IDPS must send an alert to, at a minimum, the ISSM and ISSO when denial of service incidents are detected.V-55395MEDIUMThe IDPS must generate an alert to, at a minimum, the ISSM and ISSO when new active propagation of malware infecting DoD systems or malicious code adversely affecting the operations and/or security of DoD systems is detected.V-55397MEDIUMTo protect against unauthorized data mining, the IDPS must prevent code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.V-55399MEDIUMTo protect against unauthorized data mining, the IDPS must prevent code injection attacks launched against application objects including, at a minimum, application URLs and application code.V-55401MEDIUMTo protect against unauthorized data mining, the IDPS must prevent SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.V-55403MEDIUMTo protect against unauthorized data mining, the IDPS must detect code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.V-55407MEDIUMTo protect against unauthorized data mining, the IDPS must detect code injection attacks launched against application objects including, at a minimum, application URLs and application code.V-55409MEDIUMTo protect against unauthorized data mining, the IDPS must detect SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.V-55597MEDIUMThe IDPS must automatically install updates to signature definitions, detection heuristics, and vendor-provided rules.