Check: APSC-DV-003080
Application Security and Development STIG:
APSC-DV-003080
(in versions v5 r3 through v4 r2)
Title
Back-up copies of the application software or source code must be stored in a fire-rated container or stored separately (offsite). (Cat II impact)
Discussion
Application developers and application administrators must take steps to ensure continuity of development effort and operations should a disaster strike. Steps include protecting back-up copies of development code and application software. Improper storage of the back-up copies can result in extended outages of the information system in the event of a fire or other situation that results in destruction of the back-up as well as the operating copy. To address this risk, copies of application software and application source code must be stored in a fire-rated container or separately (offsite) from the operational or development environments.
Check Content
When reviewing a COTS or GOTS application, verify that a back-up copy of the software is stored in a fire rated container or is stored separately (offsite) from the operational environment. Determine if application development is done in-house. If application development occurs in-house and source code is available, verify a back-up copy of the source code is kept in a fire-rated container or stored offsite from the development environment. If back-up copies of the application software or source code are not stored in a fire-rated container or stored separately (offsite) from their respective environments, this is a finding.
Fix Text
Store a back-up copy of the application software and source code in a fire-rated container or store it separately (offsite) from their respective environments.
Additional Identifiers
Rule ID: SV-222639r879887_rule
Vulnerability ID: V-222639
Group Title: SRG-APP-000516
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
CCI-000540 |
The organization protects the confidentiality, integrity, and availability of backup information at storage locations. |