|Finding ID||Version||Rule ID||IA Controls||Severity|
|Protection of log data includes ensuring log data is not accidentally lost or deleted. Backing up log records to an unrelated system or onto separate media than the system the web server is actually running on helps to ensure that, in the event of a catastrophic system failure, the log records will be retained.|
|Apache Server 2.4 Windows Server Security Technical Implementation Guide||2022-12-14|
|Check Text ( C-15528r277451_chk )|
| Interview the Information System Security Officer (ISSO), System Administrator (SA), Web Manager, Webmaster, or developers as necessary to determine whether a tested and verifiable backup strategy has been implemented for web server software as well as all web server data files. |
Who maintains the backup and recovery procedures?
Do you have a copy of the backup and recovery procedures?
Where is the off-site backup location?
Is the contingency plan documented?
When was the last time the contingency plan was tested?
Are the test dates and results documented?
If there is not a backup and recovery process for the web server, this is a finding.
|Fix Text (F-15526r277452_fix)|
|Document the web server backup procedures.|