Check: OSX00675 M6
MACOSX 10.6:
OSX00675 M6
(in version v1 r3)
Title
System Recovery Backup procedures must be configured to comply with DoD requirements. (Cat III impact)
Discussion
Recovery of a damaged or compromised system in a timely basis is difficult without a system information backup. A system backup will usually include sensitive information, such as user accounts that could be used in an attack. As a valuable system resource, the system backup should be protected and stored in a physically secure location.
Check Content
Interview the SA to determine if system recovery backup procedures are in place complying with DoD requirements. Any of the following would be a finding: • The site does not maintain emergency system recovery data. • The emergency system recovery data is not protected from destruction and stored in a locked storage container. • The emergency system recovery data has not been updated following the last system modification.
Fix Text
Implement data backup procedures complying with DoD requirements.
Additional Identifiers
Rule ID: SV-37320r1_rule
Vulnerability ID: V-25375
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |