Hi Experts,
IDS signature tuning can get quite involved.
To make sure nothing important is overlooked, is there a Check List that can be used?
If not, what are some of the critical items that should be known beforehand?
A couple items are obvious e.g. type of OS's used and what servers must never be blocked. But, I'm sure there's a whole list of things that should be considered.
Any feedback would be greatly appreciated.