20.66 Ensure 'The system uses a host-based intrusion detection or prevention system'

Information

This policy setting ensures that the operating system (OS) has a host-based intrusion detection (HIDS) or prevention system (HIPS) installed.

A properly configured Host-based Intrusion Detection System (HIDS) or Host-based Intrusion Prevention System (HIPS) provides another level of defense against unauthorized access to critical servers. With proper configuration and logging enabled, such a system can stop and/or alert for attempts to gain unauthorized access to resources.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Install a HIDS or HIPS on each server.

Impact:

A host-based intrusion detection (HIDS) or prevention system (HIPS) must be installed on the system.

See Also

https://workbench.cisecurity.org/benchmarks/15105

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: f383f2968b135ceda880b06637ffca830d1e21c5f952fca1b1b779f9fbda5e8f