The main purpose of an IDS is to detect and report malicious or suspicious activity on a network or a host. If an IDS fails to identify actual attacks, it means that the IDS is not functioning properly or effectively, and it exposes the organization to serious security risks and potential damage. This is the most concerning scenario for an IS auditor, as it indicates a major deficiency in the IDS performance and configuration. ReferencesWhat is an intrusion detection system (IDS)?What is Intrusion Detection Systems (IDS)? How does it Work?When reviewing an intrusion detection system (IDS), an IS auditor ...Intrusion Detection Systems (IDS)-An Overview with a Generalized ...An overview of issues in testing intrusion detection systems - NISTA Review of Intrusion Detection Systems and Their ...