20.66 Ensure 'The system uses a host-based intrusion detection or prevention system'

Information

This policy setting ensures that the operating system (OS) has a host-based intrusion detection (HIDS) or prevention system (HIPS) installed.

A properly configured Host-based Intrusion Detection System (HIDS) or Host-based Intrusion Prevention System (HIPS) provides another level of defense against unauthorized access to critical servers. With proper configuration and logging enabled, such a system can stop and/or alert for attempts to gain unauthorized access to resources.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Install a HIDS or HIPS on each server.

Impact:

A host-based intrusion detection (HIDS) or prevention system (HIPS) must be installed on the system.

See Also

https://workbench.cisecurity.org/benchmarks/18857

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: 4156ee2484040431cabd02110f9a990ce718aae2050d95f3b89679bd75be1723