Check: IISW-SV-000116
Microsoft IIS 8.5 Server STIG:
IISW-SV-000116
(in versions v2 r7 through v1 r3)
Title
The log data and records from the IIS 8.5 web server must be backed up onto a different system or media. (Cat II impact)
Discussion
Protection of log data includes assuring log data is not accidentally lost or deleted. Backing up log records to an unrelated system or onto separate media than the system the web server is actually running on helps to assure that, in the event of a catastrophic system failure, the log records will be retained.
Check Content
The IIS 8.5 web server and website log files should be backed up by the system backup. To determine if log files are backed up by the system backup, determine the location of the web server log files and each website's log files. Open the IIS 8.5 Manager. Click the IIS 8.5 server name. Click the "Logging" icon. Under "Log File" >> "Directory" obtain the path of the log file. Once all locations are known, consult with the System Administrator to review the server's backup procedure and policy. Verify the paths of all log files are part of the system backup. Verify log files are backed up to an unrelated system or onto separate media than the system the web server is running on. If the paths of all log files are not part of the system backup and/or not backed up to a separate media, this is a finding.
Fix Text
Configure system backups to include the directory paths of all IIS 8.5 web server and website log files.
Additional Identifiers
Rule ID: SV-214406r879582_rule
Vulnerability ID: V-214406
Group Title: SRG-APP-000125-WSR-000071
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001348 |
The information system backs up audit records on an organization-defined frequency onto a different system or system component than the system or component being audited. |
Controls
Number | Title |
---|---|
AU-9 (2) |
Audit Backup On Separate Physical Systems / Components |