Skip to main content
Category: Logging and Monitoring

Intrusion Detection

Also known as: IDS, Intrusion Detection System, Network Intrusion Detection, Host Intrusion Detection
Simply put

Intrusion detection is the practice of watching a computer system or network for signs that something suspicious or malicious may be happening. A system that performs this function, called an intrusion detection system (IDS), monitors traffic and activity and raises alerts when it identifies known threats or unusual behavior. It helps organizations become aware of possible security incidents so they can respond, but on its own it typically detects and reports rather than blocks activity.

Formal definition

Intrusion detection is the process of monitoring events occurring in a computer system or network and analyzing them for signs of possible incidents, such as violations or imminent threats of violation of security policies. An intrusion detection system (IDS) is the tool or application that implements this process; network-based IDSs typically capture and analyze network packets by listening on a network segment or switch to identify known attack signatures, suspicious patterns, or unauthorized access, while host-based approaches monitor activity on individual systems. Detection commonly relies on signature-based matching against known threats and, depending on the implementation, behavioral or anomaly-based analysis. An IDS generally focuses on detection and alerting; prevention capabilities that actively block traffic are associated with intrusion prevention systems (IPS), and the two functions are often combined. In the context of SOC 2 and ISO 27001, intrusion detection may support monitoring controls, but the specific controls implemented and their scope depend on the engagement, applicable Trust Services Criteria, and the ISMS scope and Statement of Applicability.

Why it matters

Intrusion detection matters because organizations cannot respond to security incidents they are unaware of. By monitoring events occurring in a computer system or network and analyzing them for signs of possible incidents, an IDS gives security teams visibility into suspicious or malicious activity that might otherwise go unnoticed until damage is done. This awareness is often a prerequisite for timely incident response, containment, and forensic investigation.

In the context of SOC 2 and ISO 27001, intrusion detection can support the monitoring controls that auditors and certification bodies expect to see. For a SOC 2 examination, detection capabilities may help demonstrate that a service organization monitors its systems in line with the applicable Trust Services Criteria, particularly the Security (Common Criteria) category. For ISO 27001, intrusion detection may be one of the technical measures selected to treat identified risks, though whether and how it applies depends on the ISMS scope and the Statement of Applicability. In both cases, the specific controls and their scope are determined by scoping decisions rather than by any universal requirement.

It is important to keep expectations bounded. An IDS typically detects and reports rather than blocks activity, so it is one layer within a broader monitoring and response program rather than a guarantee against compromise. The presence of intrusion detection does not by itself attest to freedom from breaches, and a SOC 2 report or ISO 27001 certificate speaks only to the controls and scope actually covered.

Who it's relevant to

Security Engineers and SOC Analysts
Practitioners who deploy, tune, and operate intrusion detection systems rely on them to surface suspicious or malicious activity for triage and investigation. They need to understand the distinction between detection-focused IDS and blocking-focused IPS to design monitoring that fits their environment, and to manage signature updates and anomaly baselines that keep alerting meaningful.
SOC 2 Compliance Managers
For those preparing for a SOC 2 examination, intrusion detection can help evidence monitoring controls aligned with the applicable Trust Services Criteria, particularly the Security (Common Criteria) category. Whether it is in scope, and how it is assessed, depends on the criteria selected and the engagement's scoping decisions rather than any fixed rule.
ISO 27001 Practitioners and ISMS Owners
Those maintaining an ISMS may select intrusion detection as a technical measure to treat identified risks. Its inclusion is informed by the risk assessment and documented in the Statement of Applicability, and it covers only the defined scope of the ISMS rather than the organization as a whole.
Auditors and GRC Professionals
Auditors and governance, risk, and compliance staff assess whether intrusion detection is implemented and operating in a manner consistent with the controls in scope. They should treat an IDS as one monitoring layer that supports incident awareness, without overstating it as a guarantee against compromise or as evidence beyond the period and scope actually examined.

Inside IDS

Network-based Intrusion Detection (NIDS)
Monitoring of network traffic to identify suspicious patterns, anomalies, or known attack signatures traversing the environment. Typically deployed at network boundaries or key segmentation points, depending on scope.
Host-based Intrusion Detection (HIDS)
Monitoring of activity on individual systems, such as file integrity changes, log events, and process behavior, to detect indicators of compromise on specific hosts.
Signature-based Detection
Identification of threats by matching observed activity against a database of known attack patterns. Effective against previously catalogued threats but limited against novel or unknown attacks.
Anomaly-based Detection
Identification of deviations from an established baseline of normal behavior, which can surface previously unseen activity but may generate false positives requiring tuning.
Alerting and Response Integration
The processes and tooling that route detection events to responsible personnel or a SIEM, supporting timely review and escalation. In most engagements, detection is coupled with defined response procedures.
Relevance to Compliance Criteria
Under SOC 2, intrusion detection can support the Security category (Common Criteria) relating to monitoring and detecting anomalies. Under ISO/IEC 27001, related activities may be addressed through Annex A reference controls selected via the Statement of Applicability, depending on the risk assessment and applicable version.

Common questions

Answers to the questions practitioners most commonly ask about IDS.

Does SOC 2 or ISO 27001 require an intrusion detection system?
Neither framework prescribes a specific intrusion detection system as universally mandatory. Under SOC 2, the Trust Services Criteria are expressed as outcomes rather than a fixed technology checklist, so whether intrusion detection is expected depends on the scope, the criteria selected, and how the auditor evaluates the design and, for a Type II, the operating effectiveness of your controls. Under ISO 27001, detection-related capabilities may be addressed through Annex A reference controls, but Annex A controls are selected via the Statement of Applicability and informed by your risk assessment rather than being blanket requirements. In most engagements, some form of monitoring or detection capability is expected, but the specific approach is driven by scope and risk.
Does having intrusion detection in place mean a SOC 2 report or ISO 27001 certificate guarantees I won't be breached?
No. A SOC 2 report attests only to the controls and the period covered, and it does not guarantee freedom from breaches; likewise, an ISO 27001 certificate covers only the defined scope of the ISMS and does not promise the absence of security incidents. Intrusion detection is a control intended to help identify potential unauthorized activity, but its presence is evidence of a control capability rather than a guarantee of security outcomes. Both the SOC 2 attestation and the ISO 27001 certification speak to the suitability and, where applicable, operating effectiveness of controls within a boundary, not to an assurance that no compromise will occur.
How does intrusion detection typically map across SOC 2 and ISO 27001?
Detection-related controls can often be mapped partially between the two frameworks, but the mapping is not one-to-one. In SOC 2, monitoring and detection activities generally support the Security category (the Common Criteria), which is the only required category, while Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on scope. In ISO 27001, related capabilities may be reflected through selected Annex A reference controls justified in the Statement of Applicability. Because the frameworks are structured differently, satisfying detection expectations in one does not automatically satisfy the other, and the correspondence depends on your scope, selected criteria, and risk assessment.
What kind of evidence supports intrusion detection controls in a SOC 2 Type II versus a Type I examination?
The nature of the evidence differs with the report type. A SOC 2 Type I assesses the suitability of the design of controls at a point in time, so evidence typically demonstrates that detection capabilities were designed and in place as of a specified date. A SOC 2 Type II assesses both design and operating effectiveness over a defined review period, whose length varies according to scoping decisions, so evidence usually needs to show that detection controls operated consistently throughout that period. The specific evidence expected depends on the auditor and the scope of the engagement.
How does the Statement of Applicability influence detection controls under ISO 27001?
In ISO 27001, the certifiable requirements are the ISMS requirements in clauses 4 through 10, while Annex A lists reference controls that are selected through the Statement of Applicability and informed by the risk assessment. This means detection-related controls are included or excluded based on documented, risk-based justification rather than being applied automatically. Note that Annex A was restructured in the 2022 revision, so the way detection-related reference controls are organized depends on the version of the standard in use, and any control references should be tied to the applicable edition.
Does the scope of my ISMS or SOC 2 engagement affect how intrusion detection is evaluated?
Yes. For ISO 27001, the certificate covers only the defined scope of the ISMS, so detection controls are typically assessed only within that boundary; systems or environments outside the scope are generally not covered. For SOC 2, the report attests only to the controls and the period covered within the defined scope, and whether detection controls receive attention depends on the systems in scope and the Trust Services Criteria selected. In both cases, the treatment of intrusion detection is shaped by the boundaries you define rather than applied uniformly across all environments.

Common misconceptions

Deploying an intrusion detection system is a mandatory control that guarantees SOC 2 or ISO 27001 compliance.
Neither framework mandates a specific tool. For SOC 2, controls are evaluated against the applicable Trust Services Criteria, and the auditor assesses whether the chosen approach meets those criteria. For ISO 27001, Annex A controls are selected via the Statement of Applicability informed by risk assessment, so the necessity depends on scope and the identified risks rather than a universal rule.
Intrusion detection prevents attacks and ensures the organization cannot be breached.
Detection systems are designed to identify and alert on suspicious activity, not necessarily to block it. A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches, and an ISO 27001 certificate covers only the defined scope of the ISMS.
Having intrusion detection satisfies the monitoring requirements of both SOC 2 and ISO 27001 equally.
Mapping between the frameworks is possible but partial, and satisfying one does not automatically satisfy the other. The way detection supports SOC 2's Common Criteria differs from how it may be reflected in ISO 27001 clause requirements and selected Annex A reference controls.

Best practices

Define the scope of intrusion detection coverage explicitly, aligning it with the systems and boundaries relevant to your SOC 2 examination or ISO 27001 ISMS scope.
Combine signature-based and anomaly-based detection where appropriate, and tune baselines regularly to reduce false positives and improve the reliability of alerts.
Integrate detection alerts with defined response and escalation procedures so that identified events are reviewed and acted upon in a timely manner.
Retain and protect detection logs and evidence in a manner that supports audit review, since a SOC 2 Type II examination evaluates operating effectiveness over the defined review period.
For ISO 27001 environments, document how detection-related controls are selected and justified in the Statement of Applicability, referencing the risk assessment and specifying the Annex A version in use.
Periodically test and validate detection capabilities, and document the results, rather than assuming continued effectiveness over time.