NET0390 - The network devices must be configured to alert the administrator of a potential attack or system failure.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The IDS or firewall is the first device that is under the sites control that has the possibility to alarm the local staff of an ongoing attack. An alert from either of these devices can be the first indication of an attack or system failure.

NOTE: Nessus did not perform this check as manual review is required. Determine what clipping levels / thresholds, specific alerts, and how notifications are performed and appropriate for your organizaiton.

Solution

Configure the IDS or firewall to alarm the SA of potential attacks or system failure.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Firewall_V8R24_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-3176r2_rule, STIG-ID|NET0390, Vuln-ID|V-3176

Plugin: Cisco

Control ID: c49575d1a79149bc8bcefd4b044fb089e6ce44fec613f485db4938f4ef81144c