IISW-SV-000116 - The log data and records from the IIS 8.5 web server must be backed up onto a different system or media.

Information

Protection of log data includes assuring log data is not accidentally lost or deleted. Backing up log records to an unrelated system or onto separate media than the system the web server is actually running on helps to assure that, in the event of a catastrophic system failure, the log records will be retained.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure system backups to include the directory paths of all IIS 8.5 web server and website log files.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_8-5_Y23M10_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(2), CAT|II, CCI|CCI-001348, Rule-ID|SV-214406r879582_rule, STIG-ID|IISW-SV-000116, STIG-Legacy|SV-91393, STIG-Legacy|V-76697, Vuln-ID|V-214406

Plugin: Windows

Control ID: a38b0a76d94d5faa80ae44701ba0372301467ada67884f6ea13b44d5ecb012b6