UCF STIG Viewer Logo

The log data and records from the Apache web server must be backed up onto a different system or media.


Overview

Finding ID Version Rule ID IA Controls Severity
V-92365 AS24-W1-000210 SV-102453r1_rule Medium
Description
Protection of log data includes ensuring log data is not accidentally lost or deleted. Backing up log records to an unrelated system or onto separate media than the system the web server is actually running on helps to ensure that, in the event of a catastrophic system failure, the log records will be retained.
STIG Date
Apache Server 2.4 Windows Server Security Technical Implementation Guide 2019-05-23

Details

Check Text ( C-91661r1_chk )
Interview the Information System Security Officer (ISSO), System Administrator (SA), Web Manager, Webmaster, or developers as necessary to determine whether a tested and verifiable backup strategy has been implemented for web server software as well as all web server data files.

Proposed Questions:
Who maintains the backup and recovery procedures?
Do you have a copy of the backup and recovery procedures?
Where is the off-site backup location?
Is the contingency plan documented?
When was the last time the contingency plan was tested?
Are the test dates and results documented?

If there is not a backup and recovery process for the web server, this is a finding.
Fix Text (F-98603r1_fix)
Document the web server backup procedures.