Skip to main content

ER-55 Pre-Kickoff - Intrusion Detection System (IDS) Policy, Configurations, and Alerts

Suzette Richards avatar
Written by Suzette Richards
Updated over 2 months ago

Screenshot of Intrusion Detection (IDS) Dashboard with Events

Provide evidence of your IDS dashboard and settings.

This evidence should demonstrate:

  • What is being monitored

  • What will trigger a notification

  • Who receives notification and how

Intrusion Detection System Configurations and Alerts

Provide an example of a notification or alert message from your IDS.

Additional Guidance

Commonly used IDS tools include:

  • AWS GuardDuty

  • Azure Defender

  • Google Cloud IDS

  • Cisco SourceFire

Example Evidence

AWS GuardDuty

GCP Cloud IDS

Azure Defender

Azure Firewall IDS

Associated Unified Control ID

Associated Framework Control

CTRL-833

REQ-40

Did this answer your question?