5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
5.5 Establish and Maintain an Inventory of Service Accounts
13.2 Deploy a Host-Based Intrusion Detection Solution
13.3 Deploy a Network Intrusion Detection Solution
13.4 Perform Traffic Filtering Between Network Segments
13.5 Manage Access Control for Remote Assets
13.6 Collect Network Traffic Flow Logs
13.7 Deploy a Host-Based Intrusion Prevention Solution
13.8 Deploy a Network Intrusion Prevention Solution
Controls
4 Controlled Use of Administrative Privileges
12 Boundary Defense
Safeguards
4.1 Maintain Inventory of Administrative Accounts
4.3 Ensure the Use of Dedicated Administrative Accounts
4.6 Use Dedicated Workstations For All Administrative Tasks
4.8 Log and Alert on Changes to Administrative Group Membership
4.9 Log and Alert on Unsuccessful Administrative Account Login
12.1 Maintain an Inventory of Network Boundaries
12.2 Scan for Unauthorized Connections Across Trusted Network Boundaries
12.3 Deny Communications With Known Malicious IP Addresses
12.4 Deny Communication Over Unauthorized Ports
12.5 Configure Monitoring Systems to Record Network Packets
12.6 Deploy Network-Based IDS Sensors
12.7 Deploy Network-Based Intrusion Prevention Systems
12.8 Deploy NetFlow Collection on Networking Boundary Devices
12.9 Deploy Application Layer Filtering Proxy Server
12.10 Decrypt Network Traffic at Proxy
Peer-to-Peer Sharing
The presence of peer-to-peer (P2P) file sharing indicates ineffective control of workstation software installation and that users may not be aware of the risks of downloading software from untrusted sources.
The ratio of events of type [File Sharing in Use] by type [Desktop Endpoint, Mobile Endpoint] is above 0.1%
Comments
Please sign in to leave a comment.