SV-20039r2_rule
V-18504
Anomaly baselines are not periodically rebuilt
NET-IDPS-027
CAT III
10
Establish procedures to update anomaly-based sensors.
Interview the IDPS administrator and determine if anomaly-based detection is deployed in the network. If implemented, ensure that any products collecting baselines for anomaly-based detection have their baselines rebuilt periodically to support accurate detection.
If the collection products do not have their baselines rebuilt periodically, this is a finding.
V-18504
False
NET-IDPS-027
Interview the IDPS administrator and determine if anomaly-based detection is deployed in the network. If implemented, ensure that any products collecting baselines for anomaly-based detection have their baselines rebuilt periodically to support accurate detection.
If the collection products do not have their baselines rebuilt periodically, this is a finding.
M
838