Firewalls, IDS, IPS, and Networking

Question OFID-03

Do you employ host-based intrusion prevention?

High RiskNo
Compliant AnswerYes

Standard Guidance

EDUCAUSE provides no guidance here

Answering "NO"

Describe your plan to implement host-based intrusion prevention system capabilities in your environment.

Answering "YES"

Describe the currently implemented host-based IPS solution(s).

Reason for Question

It is important to have preventive capabilities in an information system to protect institutional data. Vendors without IPSs implemented should raise concerns. Compensating controls need future evaluation, if provided by the vendor.

Follow-Up Inquiries

Ask the vendor to summarize why host-based intrusion prevention tools are not implemented in their environment. What compensating controls are in place to detect malicious activity and to actively prevent its function.

HECVAT Pro Advice

[Add expert insights and best practices]

Implementation Tips

[Add practical steps for SME SaaS vendors]


[Add common questions related to this HECVAT item]


[Add links to relevant articles or tools]