Skip to main content
CUI

STIG Rule - xccdf_mil.disa.stig_group_V-225227

xccdf_mil.disa.stig_group_V-225227

xccdf_mil.disa.stig_rule_SV-225227r960936_rule

CAT II

CAS and policy configuration files must be backed up.

From: Microsoft DotNet Framework 4.0 Security Technical Implementation Guide (VV2R7R7)

Description

<VulnDiscussion>A successful disaster recovery plan requires that CAS policy and CAS policy configuration files are identified and included in systems disaster backup and recovery events. Documentation regarding the location of system and application specific CAS policy configuration files and the frequency in which backups occur is required. If these files are not identified and the information is not documented, there is the potential that critical application configuration files may not be included in disaster recovery events which could lead to an availability risk.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

Check Procedure

No check procedure available.

Fix Text

All CAS policy and policy configuration files must be included in the system backup. All CAS policy and policy configuration files must be backed up prior to migration, deployment, and reconfiguration. CAS policy configuration files must be included in disaster recovery plan documentation.

CCI Reference

CCI-000164
Created
2026-03-12 19:38:13
Last Updated
2026-03-12 19:38:13
CUI