Check: SRG-APP-000226-UEM-000137
Unified Endpoint Management Agent SRG:
SRG-APP-000226-UEM-000137
(in version v1 r0.1)
Title
In the event of a system failure, the UEM server must preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes. (Cat II impact)
Discussion
Failure to a known state can address safety or security in accordance with the mission/business needs of the organization. Failure to a known secure state helps prevent a loss of confidentiality, integrity, or availability in the event of a failure of the information system or a component of the system. Preserving application state information helps to facilitate application restart and return to the operational mode of the organization with less disruption to mission-essential processes.
Check Content
Verify the UEM server preserves any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes, in the event of a system failure. If the UEM server does not preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes, in the event of a system failure, this is a finding.
Fix Text
Configure the UEM server to preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes, in the event of a system failure,
Additional Identifiers
Rule ID: SRG-APP-000226-UEM-000137_rule
Vulnerability ID: SRG-APP-000226-UEM-000137
Group Title: SRG-APP-000226-UEM-000137
Expert Comments
CCIs
| Number | Definition |
|---|---|
| CCI-001665 |
Preserve organization-defined system state information in the event of a system failure. |
Controls
| Number | Title |
|---|---|
| SC-24 |
Fail in Known State |