Host-Based Intrusion Detection
What is Host-Based Intrusion Detection?
A security system installed on individual hosts that monitors system calls, file modifications, and logs to detect suspicious activity on that specific device.
Frameworks that govern host-based intrusion detection
What the standards actually require on host-based intrusion detection
Requirements naming host-based intrusion detection across 3 standards, quoted from the control text.
Deploy a host-based intrusion detection solution on enterprise assets, where appropriate and/or supported.
CIS-13.2 · Deploy a Host-Based Intrusion Detection Solution →Host-based intrusion detection/prevention system to identify anomalous behaviour and known malicious activity.
ASD37-29 · Host-based IDS/IPS (Very Good) →Apply NIST SP 800-146 Chapter 7 IaaS operational recommendations to every IaaS service consumed. Coverage must include (a) infrastructure-as-code as the canonical provisioning method (no manual console provisioning of production), (b) base image and template h...
NISTSP146-4 · IaaS Operational Recommendations and Workload Hardening →Questions people ask about host-based intrusion detection
What is Host-Based Intrusion Detection?
Why is Host-Based Intrusion Detection important for compliance?
Which compliance frameworks address Host-Based Intrusion Detection?
Where can I learn more about Host-Based Intrusion Detection?
See how Host-Based Intrusion Detection applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.