The IDPS must be configured to remove or disable non-essential features, functions, and services of the IDPS application.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-206879
SRG-NET-000131-IDPS-00097
SV-206879r382903_rule
Medium
Description
An IDPS can be capable of providing a wide variety of capabilities. Not all of these capabilities are necessary. Unnecessary services, functions, and applications increase the attack surface (sum of attack vectors) of a system. These unnecessary capabilities are often overlooked and therefore may remain unsecured.
This requirement applies to unnecessary features of the IDPS application itself.