| name | cis-aws-storage-6.3 |
| description | Ensure functionality of Endpoint Detection and Response (EDR) |
| category | cis-storage-services |
| version | 1.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","storage","edr","endpoint-detection","security","threat-detection","malware"] |
| cis_id | 6.3 |
| cis_benchmark | CIS AWS Storage Services Benchmark v1.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-storage-6.1","cis-aws-storage-6.2","cis-aws-storage-6.4"] |
| prerequisites | [] |
| severity_boost | {} |
CIS 6.3: Ensure functionality of Endpoint Detection and Response (EDR) (Manual)
Profile Applicability
Description
Establish and maintain an effective Endpoint Detection and Response (EDR) system to proactively monitor, detect, and respond to security threats on endpoints such as computers, mobile devices, and servers. This involves deploying EDR software that continuously collects data from endpoints, analyzes this data for signs of malicious activity, and provides real-time alerts and detailed incident reports. Regularly test and update the EDR system to ensure it can accurately identify and mitigate advanced threats, including zero-day exploits and sophisticated malware, ensuring comprehensive protection and swift response to potential security incidents.
Rationale
Ensuring the functionality of Endpoint Detection and Response (EDR) systems is essential for early detection and swift response to security threats on endpoints. These systems continuously monitor and analyze endpoint data, providing real-time alerts and detailed incident reports to identify and mitigate potential threats. Regular testing and updates of the EDR system ensure it remains effective against advanced threats, maintaining comprehensive protection for the organization's assets.
Impact
Implementing and maintaining EDR requires:
- Deployment of EDR software on all endpoints
- Continuous monitoring and analysis infrastructure
- Regular testing and updates
- Trained security personnel to respond to alerts
- Integration with incident response procedures
Audit Procedure
Via AWS Console
-
Preparing the Environment for EDR:
- Before getting started with EDR, you must prepare the environment that you want to back up.
-
Preparing the Source Server:
- Allow direct access to Elastic Disaster Recovery and Amazon S3 AWS service API endpoints through HTTPS protocol (TCP port 443).
- Direct outbound TCP port 1500 from the source server to the staging area subnet, which contains the replication servers.
-
Preparing the Staging Area Subnet:
- Allow Direct access to EDR, S3, and EC2 through HTTPS protocol (TCP port 443)
- Direct inbound TCP port 1500 for replication traffic
-
Accessing the AWS Elastic Disaster Recovery Console:
- Search for "AWS Elastic Disaster Recovery" in the AWS Console.
- Select "Elastic Disaster Recovery"