9.3 Protecting Backups

Information

Backups of your database should be stored securely in a location with full access for administrators, read and execute access for group, and no access for users.

Rationale:

Backups may contain sensitive data that attackers can use to retrieve valuable information about the organization.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Define a security policy for all backups that specifies the privileges they should be assigned.

See Also

https://workbench.cisecurity.org/benchmarks/10752

Item Details

Category: CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CP-9, 800-53|SC-28, CSCv7|10.4

Plugin: IBM_DB2DB

Control ID: ea6d2ddc4925017ba558be48ee629124c3cd09a059ef8724652be5457d5ff4d5