STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must conduct backups of the configuration at a weekly or organization-defined frequency and store on a separate device.

DISA Rule

SV-266096r1024630_rule

Vulnerability Number

V-266096

Group Title

SRG-APP-000516-NDM-000341

Rule Version

F5BI-DM-300060

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Document this process in the system security plan (SSP) and perform periodic manual backups. This process backs up the current configuration. Backups must be weekly or a documented organization-defined frequency.

From the BIG-IP GUI:
1. System.
2. Archives.
3. Create.

From the BIG-IP console, type the following command:

tmsh save sys ucs <name>

Check Contents

From the BIG-IP GUI:
1. System.
2. Archives.
3. Review the list of archives to verify backups are conducted in accordance with the local backup policy.

From the BIG-IP console, type the following command:

tmsh list sys ucs

If the BIG-IP appliance is not configured to back up at system-level information weekly or at an organization-defined frequency this is a finding.

Vulnerability Number

V-266096

Documentable

False

Rule Version

F5BI-DM-300060

Severity Override Guidance

From the BIG-IP GUI:
1. System.
2. Archives.
3. Review the list of archives to verify backups are conducted in accordance with the local backup policy.

From the BIG-IP console, type the following command:

tmsh list sys ucs

If the BIG-IP appliance is not configured to back up at system-level information weekly or at an organization-defined frequency this is a finding.

Check Content Reference

M

Target Key

5639