1.12 WN16-00-000140

Information

Servers must have a host-based intrusion detection or prevention system.

GROUP ID:V-224830
RULE ID:SV-224830r991589

A properly configured Host-based Intrusion Detection System (HIDS) or Host-based Intrusion Prevention System (HIPS) provides another level of defense against unauthorized access to critical servers. With proper configuration and logging enabled, such a system can stop and/or alert for many attempts to gain unauthorized access to resources.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Install a HIDS or HIPS on each server.

See Also

https://workbench.cisecurity.org/benchmarks/23093

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: bc9d8a8cadd5a3dcb5e0c7d60fbd91c8fff04a99ae0ed161987d1ad4eaadf9ab