WA140 IIS6 - Web server content and configuration files must be part of a routine backup program.


Backing up web server data and web server application software after upgrades or maintenance ensures that recovery can be accomplished up to the current version. It also provides a means to determine and recover from subsequent unauthorized changes to the software and data.

A tested and verifiable backup strategy will be implemented for web server software as well as all web server data files. Backup and recovery procedures will be documented and the Web Manager or SA for the specific application will be responsible for the design, test, and implementation of the procedures.

The site will have a contingency processing plan/disaster recovery plan that includes web servers. The contingency plan will be periodically tested in accordance with DoDI 8500.2 requirements.

The site will identify an off-site storage facility in accordance with DoDI 8500.2 requirements. Off-site backups will be updated on a regular basis and the frequency will be documented in the contingency plan.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.


Document the backup procedures.

See Also


Item Details


References: 800-53|CP-9, CAT|III, Rule-ID|SV-38172r2_rule, STIG-ID|WA140_IIS6, Vuln-ID|V-6485

Plugin: Windows

Control ID: 54bf9051d6387903580a068735f44762d42e98fb2c321e725ffd7e9ba6ac9291