UCF STIG Viewer Logo

Email critical software copies must be stored off-site in a fire-rated container.


Overview

Finding ID Version Rule ID IA Controls Severity
V-18884 EMG3-010 EMail SV-20681r3_rule COSW-1 Medium
Description
There is always potential that accidental loss can cause system loss and that restoration will be needed. In the event that the installation site is compromised, damaged or destroyed copies of critical software media may be needed to recover the systems and become operational. Copies of the operating system (OS) and other critical software, such as email services applications must be created and stored off-site in a fire-rated container. If a site experiences loss or compromise of the installed software libraries, available copies can reduce the risk and shorten the time period for a successful email services recovery.
STIG Date
Email Services Policy STIG 2015-08-07

Details

Check Text ( C-22538r3_chk )
Access the EDSP and review the email application software offline storage plan. Examine artifacts showing that copies exist and are stored off-site in fire-rated containers.

If an email software copy exists and is stored off-site in a fire-rated container, this is not a finding.
Fix Text (F-19497r3_fix)
Create email software copies for use in recovering systems, and store them off-site and in fire-rated containers. Document the off-site storage details in the EDSP.