10.2 Intrusion Detection and Prevention, and Privacy in Change Management

Key Takeaways

  • An IDS monitors and alerts, while an IPS sits inline and can block traffic; both come in network-based and host-based forms.

  • Detection methods include signature-based, anomaly-based, and stateful protocol analysis, as described in NIST SP 800-94.

  • IDS sensors and packet captures contain personal data, so minimize payload capture, restrict access, and set short retention.

  • Honeytokens, such as fake customer records or credentials that no legitimate process uses, give high-confidence alerts of unauthorized access to personal data.

  • Change management should trigger privacy review for changes touching personal data and run automated tests that verify privacy defaults survive every patch and upgrade.

Last updated: October 2026

10.2 Intrusion Detection and Prevention, and Privacy in Change Management

Quick Summary: Two everyday security disciplines carry privacy consequences. Intrusion detection and prevention helps detect attacks against personal data, but it also inspects traffic full of personal data, so it needs its own privacy controls. Change management governs patches, upgrades, and releases; when it ignores privacy, an update can quietly reset settings, add data collection, or expose fields that were hidden.


Intrusion Detection and Prevention Systems

An intrusion detection system (IDS) monitors network traffic or host activity and raises alerts about suspected attacks. An intrusion prevention system (IPS) does the same but sits inline, so it can block or drop malicious traffic as it happens. NIST SP 800-94, Guide to Intrusion Detection and Prevention Systems, groups them as follows:

TypeWhere It WatchesExample Detections
Network-based (NIDS/NIPS)Traffic on network segmentsSQL injection strings, scanning, command-and-control traffic
Host-based (HIDS/HIPS)Activity on a single server or endpointUnexpected processes, file changes, privilege escalation
WirelessWireless network activityRogue access points
Network behavior analysisTraffic flows and volumesUnusual large transfers, new external destinations

Related tools include web application firewalls (WAFs), which block attacks against web applications, and endpoint detection and response (EDR) agents, which record detailed endpoint activity.

Detection Methods

  • Signature-based: matches known attack patterns. Accurate for known threats, blind to new ones.
  • Anomaly-based: learns a baseline and flags deviations, such as a service account that normally reads 50 records an hour suddenly reading 50,000. Better at new threats, but noisier.
  • Stateful protocol analysis: compares activity against expected protocol behavior to spot misuse.

Using IDS/IPS to Protect Personal Data

  • Watch the paths to personal data: place sensors at the boundaries of networks and hosts that hold sensitive data, and monitor egress for exfiltration.
  • Add data-aware signals: combine IDS alerts with database activity monitoring and data loss prevention, so a large export of customer records is flagged even when the attacker uses valid credentials.
  • Deploy honeytokens: plant fake customer records, API keys, or credentials that no legitimate process ever touches. Any access to them is a high-confidence alert that someone is browsing or stealing data.
  • Tune deliberately: false positives cause alert fatigue, and false negatives miss real breaches. Review rules after each incident and test them against realistic attacks.

The Privacy Risks of IDS/IPS Themselves

Intrusion detection inspects the very data it protects, so it needs its own privacy controls:

  • Minimize payload capture. Many detections need only headers and metadata; store full packet captures only when an alert fires and only briefly.
  • Control TLS inspection. Decrypting traffic exposes passwords, health searches, and banking sessions. Exempt sensitive categories (for example, health and banking sites) where policy and law require, and tell employees about inspection.
  • Restrict and log analyst access to captured data and alerts.
  • Set retention limits for logs, alerts, and captures, and include them in the data inventory.
  • Respect workplace monitoring rules when sensors observe employees (Section 12.3).

Privacy in Change Management: Patches and Upgrades

Change management is the controlled process for proposing, assessing, approving, testing, deploying, and reviewing changes. Its main security purpose is to apply fixes quickly without breaking systems. Its privacy purpose is to make sure changes do not create new collection, new disclosure, or weaker settings.

How Changes Create Privacy Problems

  • Defaults reset by upgrades: a release that migrates settings can silently set privacy options back to permissive defaults.
  • New SDK versions: an analytics or ad SDK upgrade can add new identifiers or data types.
  • Schema migrations: a new column or API field can expose data that was previously hidden.
  • Debug logging left on: verbose logging enabled during a fix can capture personal data.
  • Data migrations: copying production data to a new platform or test environment without masking.

Real incidents show the pattern. In 2018, a Facebook bug set the default audience of new posts to public for about 14 million users for several days. In early 2019, Twitter disclosed that an Android bug, present since 2014, had turned off the "Protect your Tweets" setting for some users who changed account settings, making their posts public.

Controls in the Change Process

  1. Privacy triggers in the change request: questions such as "Does this change add, alter, or expose personal data, add a third-party SDK, or change a privacy default?" route the change to privacy review and, where needed, a DPIA update.
  2. Automated privacy regression tests: assert that privacy defaults, consent gating, masking, and retention behavior are unchanged after each build.
  3. Configuration drift detection: compare running configurations with approved baselines.
  4. Staged rollouts and feature flags: release to a small population first, monitor data flows and complaints, and keep the ability to roll back.
  5. Timely patching: prioritize vulnerabilities known to be exploited, such as those on CISA's Known Exploited Vulnerabilities catalog, because unpatched systems are a leading cause of breaches.
  6. Post-implementation review: confirm data flows match what was approved and update the inventory and notices.
  7. Emergency changes: fast-tracked fixes still need after-the-fact privacy review and documentation.
Test Your Knowledge

A security team wants a control that can automatically block SQL injection attempts against the customer database's web front end as they occur. Which tool fits this requirement?

A

A quarterly authenticated vulnerability scan of the web servers and database hosts

B

A passive network intrusion detection system connected to a mirror port

C

An inline intrusion prevention system or web application firewall in the traffic path

D

A host-based file integrity monitor on the database server

Test Your Knowledge

A company wants a high-confidence alert if anyone browses or exports customer records without authorization, including insiders with valid credentials. Which technique provides this with very few false positives?

A

Encrypting the database backups with a new key

B

Raising the signature-based IDS sensitivity so that it alerts on every single database query from any account

C

Requiring stronger passwords for database administrators

D

Planting honeytoken records that no legitimate process uses and alerting on any access to them

Test Your Knowledge

After a routine mobile app upgrade, users discover that their profiles, previously set to private, are now visible to everyone. Which change management control would most likely have caught this before release?

A

Turning on verbose debug logging during the upgrade

B

Automated regression tests that assert privacy settings survive the upgrade

C

A larger change advisory board that meets weekly to discuss every release in person

D

Faster deployment of all upgrades to every user at once to reduce downtime and support costs

Sections you finish are checked off in the contents.