Check: EMG3-007 EMail
Email Services Policy:
EMG3-007 EMail
(in version v1 r4)
Title
E-mail backups do not meet schedule or storage requirements. (Cat II impact)
Discussion
Hardware failures or other (sometimes physical) disasters can cause data loss to active applications, and the need for expedient recovery. Ensuring that backups are conducted on an agreed schedule creates a timely copy from which to recover active systems. Storing backup contents at a separate physical location protects the backup data from site-specific physical disasters. Backup schedule and storage location are determined in accordance with the MAC category and confidentiality level.
Check Content
Procedure: Interview the IAO. Access the site's System Security Plan. Review backup frequency schedule. Also, review file locations, access protections and procedures for offline files, and storage methods. Criteria: If E-mail backups are conducted on schedule and are stored appropriately, this is not a finding.
Fix Text
Procedure: Perform followup to ensure that E-mail backups are conducted on schedule and are stored appropriately
Additional Identifiers
Rule ID: SV-20679r1_rule
Vulnerability ID: V-18883
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |