STIGQter STIGQter: STIG Summary: Redis Enterprise 6.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

In the event of a system failure, Redis Enterprise DBMS must preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes.

DISA Rule

SV-251241r961125_rule

Vulnerability Number

V-251241

Group Title

SRG-APP-000226-DB-000147

Rule Version

RD6X-00-010700

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the Redis Enterprise web UI, select databases and then select the individual databases.

For each database, select configuration.

Check the box and configure the following as defined by the ISSO/ISSM: "Persistence", "Periodic backup", and "Alerts"

Ensure that organizationally defined path for the centralized log server is also applied and configured external to the database.

Check Contents

In the Redis Enterprise web UI, select settings and then alerts.

Verify the alerts documented by the ISSO/ISSM are checked.

If required alerts are not checked, this is a finding.

In the Redis Enterprise web UI, select databases, then select the individual databases.

For each database, select configuration.

Verify that "Persistence", "Periodic backup", and "Alerts" are all configured as organizationally defined and documented by the ISSO or ISSM.

Verify that organizationally defined path for the centralized log server is also applied and configured external to the database.

If any of these items are not configured as documented, this is a finding.

Vulnerability Number

V-251241

Documentable

False

Rule Version

RD6X-00-010700

Severity Override Guidance

In the Redis Enterprise web UI, select settings and then alerts.

Verify the alerts documented by the ISSO/ISSM are checked.

If required alerts are not checked, this is a finding.

In the Redis Enterprise web UI, select databases, then select the individual databases.

For each database, select configuration.

Verify that "Persistence", "Periodic backup", and "Alerts" are all configured as organizationally defined and documented by the ISSO or ISSM.

Verify that organizationally defined path for the centralized log server is also applied and configured external to the database.

If any of these items are not configured as documented, this is a finding.

Check Content Reference

M

Target Key

5443