8.2.8 Backup Your Password In Case Stash File is Inaccessible or Corrupted

Information

If the keystore is inaccessible, there is no way to decrypt the data in the database. Therefore, protecting and backing up the password to the keystore is important to avoid data loss.

Rationale:

Ensure that you back up your passwords, in addition to using a stash file. This applies particularly to the password used for a local keystore file. Should your stash file ever become corrupted, you will need to manually supply the password. If you forget the password, and do not created a backup, access to your keys and data is lost.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

You may use a password manager to store the password in a secure manner.

See Also

https://workbench.cisecurity.org/benchmarks/10752

Item Details

Category: CONTINGENCY PLANNING

References: 800-53|CP-9

Plugin: IBM_DB2DB

Control ID: 83a80b7d399e20b4b2a8b7deffb836b9e76fae321dec3beadd748a9d3240672e