STIGQter STIGQter: STIG Summary: VMware ESX 3 Server Version: 1 Release: 2 Benchmark Date: 22 Jul 2016: Virtual machines are not backed up in accordance with the MAC level.

DISA Rule

SV-16855r1_rule

Vulnerability Number

V-15913

Group Title

Virtual machines are not backed up

Rule Version

ESX1140

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Backup all virtual machines according to the MAC level.

Check Contents

1. Determine the MAC level of the virtual machines by asking the IAO/SA.
2. Once the MAC level is determined, locate the backup media or storage location.
For MAC I servers, a redundant secondary system is required that is not colocated.
For MAC II servers, daily backups are required with recovery media stored offline.
For MAC III servers, backups must be performed weekly.
3. Depending on the MAC level, verify the virtual machines are backed up to media or storage within the guidelines of the MAC level. If they are not, this is a finding.

Vulnerability Number

V-15913

Documentable

False

Rule Version

ESX1140

Severity Override Guidance

1. Determine the MAC level of the virtual machines by asking the IAO/SA.
2. Once the MAC level is determined, locate the backup media or storage location.
For MAC I servers, a redundant secondary system is required that is not colocated.
For MAC II servers, daily backups are required with recovery media stored offline.
For MAC III servers, backups must be performed weekly.
3. Depending on the MAC level, verify the virtual machines are backed up to media or storage within the guidelines of the MAC level. If they are not, this is a finding.

Check Content Reference

M

Responsibility

[Virtual Machine Administrator]

Target Key

1386

Comments