Procedure Step:Intrusion Detection System
Audit Step:
Determine whether the agency has taken adequate steps to implement an IDS for the application according to State IS Policy including:
- Identifying critical host computers (such as user workstations, peripherals [i.e., printers], specialized servers including web servers, or network components [i.e., firewalls, routers, and switches]);
- Conducting penetration tests to validate potential vulnerabilities;
- Installing an approved IDS on all critical hosts and any host that is storing or processing sensitive information;
- Installing an approved IDS on all critical network segments; and,
- Scanning critical hosts monthly and critical networks quarterly with an accepted vulnerability-scanning product (i.e., ISS) to ensure IDS's continue to address known vulnerabilities.
Purpose:
To obtain an understanding of application information security controls.

