1.16.6 Restrict access to backup files to System Administrators

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Level 1, Scorable
Restrict access to the backup files to System Administrators.
Backup files contain data that is owned by the company. These backups may contain very sensitive information such as credit card numbers
or social security numbers. It is essential that backup files are not able to be copied by unauthorized personnel. In addition, backups
are required to restore a database in the event of an emergency. Unauthorized personnel must not be allowed to modify, move, or delete
these files.
ref. https://benchmarks.cisecurity.org/tools2/sqlserver/CIS_Microsoft_SQL_Server_2005_Benchmark_v2.0.0.pdf, pg 139.
Note: Update {BACKUP_FILE} with the proper value for the local environment.