SQL2-00-017800 - SQL Server backup procedures must be defined, documented, and implemented.

Information

SQL Server backup is a critical step in maintaining data assurance and availability.

User-level information is data generated by the information system and/or application users. In order to assure availability of this data in the event of a system failure, DoD organizations are required to ensure user-generated data is backed up at a defined frequency. This includes data stored on file systems, within SQL Server or within any other storage media.

Applications performing backups must be configured to back up user-level information per the DoD-defined frequency.

SQL Server Database backups provide the required means to restore databases after compromise or loss. Backups help reduce the vulnerability to unauthorized access or hardware loss.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Develop, document, and implement database backup procedures.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_SQL_Server_2012_V1R20_STIG.zip

Item Details

Category: CONTINGENCY PLANNING

References: 800-53|CP-9a., CAT|II, CCI|CCI-000535, Rule-ID|SV-53283r2_rule, STIG-ID|SQL2-00-017800, Vuln-ID|V-40929

Plugin: MS_SQLDB

Control ID: 0412aee3c52acd97027ac25a9718e131da212bac6d345c46101c19da0358758b