9.3 Protecting Backups

Information

Backups of your database should be stored securely in a location with full access for administrators, read and execute access for group, and no access for users.

Rationale:

Backups may contain sensitive data that attackers can use to retrieve valuable information about the organization.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Define a security policy for all backups that specifies the privileges they should be assigned.

See Also

https://workbench.cisecurity.org/benchmarks/10752

Item Details

Category: CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CP-9, 800-53|SC-28, CSCv7|10.4

Plugin: IBM_DB2DB

Control ID: 30e7f57c8148e11514a2c959ac7b48462a5ea6c182696f30a12b6b0b69a3b327