STIGQter STIGQter: STIG Summary: Active Directory Domain Security Technical Implementation Guide (STIG) Version: 2 Release: 13 Benchmark Date: 26 Apr 2019:

Active Directory data must be backed up daily for systems with a Risk Management Framework categorization for Availability of moderate or high. Systems with a categorization of low must be backed up weekly.

DISA Rule

SV-31547r3_rule

Vulnerability Number

V-25385

Group Title

Directory Data Backup

Rule Version

DS00.0160_AD

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Update the organization's procedures for the backing up active directory data.
Ensure the frequency at which active directory data is backed up is as follows:
If the Availability categorization of the domain is low, this must be at least weekly.
If the Availability categorization of the domain is moderate or high, this must be at least daily.
Ensure the type of backup is appropriate to capturing the directory data. For AD domain controllers, this must include a System State data backup.

Check Contents

Review the organization's procedures for the backing up active directory data.
Verify the frequency at which active directory data is backed up.
If the Availability categorization of the domain is low, this must be at least weekly.
If the Availability categorization of the domain is moderate or high, this must be at least daily.
Verify the type of backup is appropriate to capturing the directory data. For AD domain controllers, this must include a System State data backup.

If any of these conditions are not met, this is a finding.

Vulnerability Number

V-25385

Documentable

False

Rule Version

DS00.0160_AD

Severity Override Guidance

Review the organization's procedures for the backing up active directory data.
Verify the frequency at which active directory data is backed up.
If the Availability categorization of the domain is low, this must be at least weekly.
If the Availability categorization of the domain is moderate or high, this must be at least daily.
Verify the type of backup is appropriate to capturing the directory data. For AD domain controllers, this must include a System State data backup.

If any of these conditions are not met, this is a finding.

Check Content Reference

M

Responsibility

Information Assurance Officer

Target Key

870

Comments