STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 3 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Microsoft DotNet Framework 4.0 Security Technical Implementation Guide

V-225227

CAT II (Medium)

CAS and policy configuration files must be backed up.

Rule ID

SV-225227r960936_rule

STIG

Microsoft DotNet Framework 4.0 Security Technical Implementation Guide

Version

V2R8

CCIs

CCI-000164

Discussion

A successful disaster recovery plan requires that CAS policy and CAS policy configuration files are identified and included in systems disaster backup and recovery events. Documentation regarding the location of system and application specific CAS policy configuration files and the frequency in which backups occur is required. If these files are not identified and the information is not documented, there is the potential that critical application configuration files may not be included in disaster recovery events which could lead to an availability risk.

Check Content

The infrastructure to enable Code Access Security (CAS) exists only in .NET Framework 2.x-4.x.

The requirement is Not Applicable (NA) for .NET Framework greater than 4.x.

(Note: The infrastructure is deprecated and is not receiving servicing or security fixes.)

Ask the System Administrator if all CAS policy and policy configuration files are included in the system backup. If they are not, this is a finding.

Ask the System Administrator if the policy and configuration files are backed up prior to migration, deployment, and reconfiguration. If they are not, this is a finding.

Ask the System Administrator for documentation that shows CAS Policy configuration files are backed up as part of a disaster recovery plan. If they have no documentation proving the files are backed up, this is a finding.

Fix Text

All CAS policy and policy configuration files must be included in the system backup. 

All CAS policy and policy configuration files must be backed up prior to migration, deployment, and reconfiguration.

CAS policy configuration files must be included in disaster recovery plan documentation.