The IPS must block malicious code.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-206889SRG-NET-000249-IDPS-00176SV-206889r1137734_ruleCCI-001243medium
Description
Configuring the IPS to blocks, drops, and/or quarantine based on local organizational incident handling procedures minimizes the impact of this code on the network.
STIGDate
Intrusion Detection and Prevention Systems Security Requirements Guide2025-09-22

Details

Check Text (C-206889r1137734_chk)

If the device being reviewed is an IDS, this is not applicable. Verify the IPS blocks malicious code. If the IPS does not block malicious code, this is a finding.

Fix Text (F-7143r1137733_fix)

Configure the IPS to block malicious code.