1.0 Overview
This policy provides policies to establish intrusion detection and security monitoring to protect resources and data on the organizational network. It provides guidelines about intrusion detection implementation of the organizational networks and hosts along with associated roles and responsibilities.

2.0 Purpose
This policy is designed both to establish procedures for notification of affected clients in the case of an intrusion event.

3.0 Scope
This policy covers every host on the organizational public network.

4.0 Objectives

  1. Increase the level of security by actively searching for signs of unauthorized intrusion.
  2. Prevent or detect the confidentiality of organizational and client data on the network.
  3. Preserve the integrity of organizational and client data on the network.
  4. Prevent unauthorized use of organizational and client systems.
  5. Keep hosts and network resources available to authorized users.
  6. Increase security by detecting weaknesses in systems and network design early.

5.0 Requirements

  1. All systems accessible from the internet must operate IT approved active intrusion detection software.
  2. All host based and network based intrusion detection systems must be checked on a daily basis at a minimum and their logs reviewed.
  3. All intrusion detection logs must be kept for a minimum or 30 days.

6.0 Notification

  1. Any suspicious or malicious activity reported by a third-party must be investigated and responded to immediately.
  2. Upon completion of investigation and resolution of the issue, the reporting party should be notified of said resolution.

7.0 Responsibilities

  1. The network administration team shall:
    1. Monitor intrusion detection systems both host based and network based.
    2. Check intrusion detection logs daily at a minimum.
    3. Determine approved intrusion detection systems and software.
    4. Act on reported incidents and take action to minimize damage, archive any hostile or unapproved software for investigation, and recommend changes to prevent future incidents..
    5. Notify affected clients as to the extent of intrusion, resolution, and plan for future preventative action.