20.65 Ensure 'The system uses a host-based intrusion detection or prevention system'

Information

This policy setting ensures that the operating system (OS) has a host-based intrusion detection (HIDS) or prevention system (HIPS) installed.

A properly configured Host-based Intrusion Detection System (HIDS) or Host-based Intrusion Prevention System (HIPS) provides another level of defense against unauthorized access to critical servers. With proper configuration and logging enabled, such a system can stop and/or alert for attempts to gain unauthorized access to resources.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Install a HIDS or HIPS on each server.

Impact:

A host-based intrusion detection (HIDS) or prevention system (HIPS) must be installed on the system.

See Also

https://workbench.cisecurity.org/benchmarks/15301

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: 0c3ffa5ae51ca0b46e5c1b8d49e4553570afcffe3d7ce7608713a183a4f42218