DG0020: Backup and recovery procedures should be developed, documented, implemented and periodically tested.

Information

Problems with backup procedures or backup media may not be discovered until after a recovery is needed. Testing and verification of procedures provides the opportunity to discover oversights, conflicts, or other issues in the backup procedures or use of media designed to be used.

NOTE: Nessus did not perform this check as it requires manual verification.

Solution

Design, document and implement backup testing and recovery verification procedures for the DBMS host and all individual database instances and either include or note the name, location, version and current revision date of any external documentation in the System Security Plan.

Include any requirements for documenting database backup and recovery testing and verification activities in the procedures.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Oracle_Database_11g_V8R19_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-24608r1_rule, STIG-ID|DG0020-ORACLE11, Vuln-ID|V-15129

Plugin: Windows

Control ID: 6d43ee4808fe96ad3bc1d0f9ce029df45a14ffb000b2f861fe98a953428a67de