STIGQter STIGQter: STIG Summary: Redis Enterprise 6.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

Redis Enterprise DBMS must fail to a secure state if system initialization fails, shutdown fails, or aborts fail.

DISA Rule

SV-251240r961122_rule

Vulnerability Number

V-251240

Group Title

SRG-APP-000225-DB-000153

Rule Version

RD6X-00-010600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To enable persistence and replication in the Redis Enterprise UI, click the databases tab. For each database that requires reconfiguration, click it and select configuration. Ensure that the replication box is checked as well as the desired persistence level.

Edit the parameters necessary to meet the desired organizational needs.

Check Contents

1. In the console UI, click the databases tab.
2. For each listed database, click it and select configuration.
3. Verify that "Persistence" is set to: "Append Only File (AOF) - fsync every write".

If the setting is not configured or not documented to be set differently, this is a finding.

4. For each listed database, click it and select configuration.
5. Verify "Replication" is set enabled.

If the setting is not configured or not documented to be set differently, this is a finding.

Vulnerability Number

V-251240

Documentable

False

Rule Version

RD6X-00-010600

Severity Override Guidance

1. In the console UI, click the databases tab.
2. For each listed database, click it and select configuration.
3. Verify that "Persistence" is set to: "Append Only File (AOF) - fsync every write".

If the setting is not configured or not documented to be set differently, this is a finding.

4. For each listed database, click it and select configuration.
5. Verify "Replication" is set enabled.

If the setting is not configured or not documented to be set differently, this is a finding.

Check Content Reference

M

Target Key

5443