WN08-00-000003 - System information backups must be created, updated, and protected.

Information

Recovery of a damaged or compromised system in a timely manner is difficult without a system information backup. A system backup will usually include sensitive information such as user accounts that could be used in an attack. As a valuable system resource, the system backup must be protected and stored in a physically secure location.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Implement system recovery procedures that include maintaining emergency system recovery data, protecting that data from destruction and storing it in a locked storage container, and updating it following each and every system modification.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_8_and_8-1_V1R23_STIG.zip

Item Details

References: CAT|III, CCI|CCI-000366, Rule-ID|SV-48019r1_rule, STIG-ID|WN08-00-000003, Vuln-ID|V-1076

Plugin: Windows

Control ID: c67e127c581f379e43d2dcdd7a2cc0273df07d188cbfc6f2ed26221496ea0c7c