Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-6661 | SAN05.001.00 | SV-6809r1_rule | COSW-1 | Medium |
Description |
---|
.Backup and recovery procedures are critical to the security and availability of the SAN system. If a system is compromised, shut down, or otherwise not available for service, this could hinder the availability of resources to the warfighter. The IAO/NSO will ensure that all fabric switch configurations and management station configuration are archived and copies of the operating system and other critical software for all SAN components are stored in a fire rated container or otherwise not collocated with the operational software. |
STIG | Date |
---|---|
Storage Area Network STIG | 2019-06-28 |
Check Text ( C-2589r1_chk ) |
---|
The reviewer will interview the IAO/NSO and view the stored information to verify that all fabric switch configurations and management station configuration are archived and copies of the operating system and other critical software for all SAN components are stored in a fire rated container or otherwise not collocated with the operational software. |
Fix Text (F-6256r1_fix) |
---|
Develop a plan that will ensure that all fabric switch configurations and management station configuration are archived and copies of the operating system and other critical software for all SAN components are stored in a fire rated container or otherwise not collocated with the operational software. Obtain CM approval for the plan and implement the plan. |