1.12 WN22-00-000120

Information

Windows Server 2022 must have a host-based intrusion detection or prevention system.

GROUP ID: V-254249
RULE ID: SV-254249r991589

A properly configured Host-based Intrusion Detection System (HIDS) or Host-based Intrusion Prevention System (HIPS) provides another level of defense against unauthorized access to critical servers. With proper configuration and logging enabled, such a system can stop and/or alert for many attempts to gain unauthorized access to resources.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Install a HIDS or HIPS on each server.

See Also

https://workbench.cisecurity.org/benchmarks/22357

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: ced8b6290b20e7329e1e769785c7dfda45ac2fd531b25e33aaaa0a8acdca8fae