Skip to main content

ER-55 Pre-Kickoff - Intrusion Detection System (IDS) Policy, Configurations, and Alerts

Suzette Richards avatar
Written by Suzette Richards
Updated this week

Screenshot of Intrusion Detection (IDS) Dashboard with Events

Provide evidence of your IDS dashboard and settings.

This evidence should demonstrate:

  • What is being monitored

  • What will trigger a notification

  • Who receives notification and how

Intrusion Detection System Configurations and Alerts

Provide an example of a notification or alert message from your IDS.

Additional Guidance

Commonly used IDS tools include:

  • AWS GuardDuty

  • Azure Defender

  • Google Cloud IDS

  • Cisco SourceFire

Example Evidence

AWS GuardDuty

GCP Cloud IDS

Azure Defender

Azure Firewall IDS

Associated Unified Control ID

Associated Framework Control

CTRL-833

LCL-42

Did this answer your question?