TTUHSC IT Policies
1.4.9 INTRUSION DETECTION
At TTUHSC, several systems are used to monitor, detect, and log intrusion attempts via the IP network. These systems include a Network Behavior and Anomaly Detection System, Intrusion Prevention Systems, firewalls, email antivirus protection for Exchange servers, and antivirus software for client computers.
The Information Technology Security Group shall monitor and audit intrusion detection logs as part of their daily job functions. Intrusion detection logs are maintained for a minimum period of two weeks. Anomalies will be investigated and appropriate measures will be taken in the event of an actual threat in accordance with the incident management procedures outlined in Section 1.4.7. Compliance with this policy is the responsibility of the Managing Director of Network, Security, and Systems.
Antivirus software provide for the blocking of virus, worm and Trojan horse programs on our email servers as well as the other computers on our network. These programs are used to block communications on various troublesome ports and block the sending of attachment types with potentially malicious content.