Rule ID
SV-216225r959010_rule
Version
V3R5
CCIs
Operating system backup is a critical step in maintaining data assurance and availability. User-level information is data generated by information system and/or application users. Backups shall be consistent with organizational recovery time and recovery point objectives.
The operations staff shall ensure that proper backups are created, tested, and archived. Ask the operator for documentation on the backup procedures implemented. If the backup procedures are not documented then this is a finding.
The operations staff shall install, configure, test, and verify operating system backup software. Additionally, all backup procedures must be documented.