Disagree
The intrusion detection system represents the secondary protection to the firewall and provides necessary indication to the responsible in case of a particular situation that requires notification. Organizations use IPS or IDS, intrusion prevention mechanism, that provide passive protection mechanism. While host-based intrusion, mechanism moves around individual hosts, application-based intrusion method is expanded to a broader application. This is further classified into anomaly based and signature-based intrusion mechanisms that the organizations can effectively deploy (Gross, 2019). The different types of IDS are (Lewis, 2017):
NIDS: Network-based IDS
HIDS: Host-based IDS
IDPS: Intrusion Detection and Prevention Systems
PIDS: Protocol-based IDS
APIDS: Application-based IDS
The primary method to isolate corporate assets from an intrusion is by isolating assets with network segmentation. The classification would demark the different departments within an organization to accounting, sales, administration and so on. Further to this, network segmentation would enable to have access control (Graff, 2018). The Sherwood Applied Business Security Architecture (SABSA) method allows an organization to classify and understand the asset that it is trying to protect in case of an intrusion (Ritchot, 2013).
References:
Graff, M. G. (2018, January 16). Defeat Ransomware Attacks with Network Segmentation. Retrieved from https://www.blackridge.us/blog/defeat-ransomware-attacks-with-network-segmentation
Gross, G. (2019, February 14).Intrusion Detection Techniques, Methods & Best Practices: Detecting Network Intrusion in 2019. Retrieved from https://www.alienvault.com/blogs/security-essentials/intrusion-detection-techniques-methods-best-practices
Lewis, K. (2017). Security Intrusion. Retrieved from https://www.sciencedirect.com/topics/computer-science/security-intrusion
Ritchot, B. (2013, August). An Enterprise Security Program and Architecture to Support Business Drivers. Retrieved from https://timreview.ca/article/713