SV-80919r1_rule
V-66429
SRG-NET-000392-IDPS-00218
JUSX-IP-000025
CAT II
10
Configure alerts for IDP attack by using the [edit security alarms potential-violation] command.
Add the option "alert" onto the rule to send an alert when that rule is invoked. Alerts should be sent only on critical and other site-selected items to prevent an excess of alerts.
[edit]
set security idp idp-policy recommended rulebase-ips rule-1 then notification log-attacks alert
Verify alerts are configured to implement this requirement.
[edit]
show security alarms potential-violation
If alerts are not configured to notify the ISSO and ISSM of potential-violation IDP events, this is a finding.
V-66429
False
JUSX-IP-000025
Verify alerts are configured to implement this requirement.
[edit]
show security alarms potential-violation
If alerts are not configured to notify the ISSO and ISSM of potential-violation IDP events, this is a finding.
M
3037