STIGQter STIGQter: STIG Summary: Oracle Database 11g Installation STIG Version: 8 Release: 20 Benchmark Date: 28 Jul 2017:

Backup and recovery procedures should be developed, documented, implemented and periodically tested.

DISA Rule

SV-24608r1_rule

Vulnerability Number

V-15129

Group Title

DBMS backup and recovery testing

Rule Version

DG0020-ORACLE11

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Design, document and implement backup testing and recovery verification procedures for the DBMS host and all individual database instances and either include or note the name, location, version and current revision date of any external documentation in the System Security Plan.

Include any requirements for documenting database backup and recovery testing and verification activities in the procedures.

Check Contents

Review documented backup testing and recovery verification procedures noted or documented in the System Security Plan.

Review evidence of implementation of testing and verification procedures by reviewing logs from backup and recovery implementation.

Logs may be in electronic or hardcopy and may include email or other notification.

If backup testing and recovery verification are not documented or noted in the System Security Plan, this is a Finding.

If evidence of backup testing and recovery verification does not exist, this is a Finding.

Vulnerability Number

V-15129

Documentable

False

Rule Version

DG0020-ORACLE11

Severity Override Guidance

Review documented backup testing and recovery verification procedures noted or documented in the System Security Plan.

Review evidence of implementation of testing and verification procedures by reviewing logs from backup and recovery implementation.

Logs may be in electronic or hardcopy and may include email or other notification.

If backup testing and recovery verification are not documented or noted in the System Security Plan, this is a Finding.

If evidence of backup testing and recovery verification does not exist, this is a Finding.

Check Content Reference

I

Responsibility

Database Administrator

Target Key

1368

Comments