Free DISA STIG and SRG Library | Vaulted

V-55359

The IDPS must perform real-time monitoring of files from external sources at network entry/exit points.

Finding ID
SRG-NET-000248-IDPS-00206
Rule ID
SV-69605r1_rule
Severity
Cat II
CCE
(None)
Group Title
SRG-NET-000248-IDPS-00206
CCI
CCI-001242
Target Key
(None)
Documentable
No
Discussion

Real-time monitoring of files from external sources at network entry/exit points helps to detect covert malicious code before it is downloaded to or executed by internal and external endpoints. Using malicious code, such as viruses, worms, Trojan horses, and spyware, an attacker may gain access to sensitive data and systems. IDPSs innately meet this requirement for real-time scanning for malicious code when properly configured to meet the requirements of this SRG. However, most products perform communications traffic inspection at the packet level.

Fix Text

Configure the IDPS to perform real-time monitoring of files from external sources at network entry/exit points.

Check Content

Verify the IDPS performs real-time monitoring of files from external sources at network entry/exit points. If the IDPS does not perform real-time monitoring of files from external sources at network entry/exit points, this is a finding.