STIGUI
V-285606CAT II — Medium severitySV-285606r1274298_rule

The Content Analysis System (CAS) must automatically perform both continuous and weekly backups of its configuration settings to a secure, remote server to ensure continuity of operations.

Rule version BCAS-ND-001900 · STIG v1 · 2026-09-16

Discussion

System-level information includes default and customized settings and security attributes, including ACLs that relate to the network device configuration, as well as software required for the execution and operation of the device. Information system backup is a critical step in ensuring system integrity and availability. If the system fails and there is no backup of the system-level information, a denial of service condition is possible for all who utilize this critical network component.

This control requires the network device to support the organizational central backup process for system-level information associated with the network device. This function may be provided by the network device itself; however, the preferred best practice is a centralized backup rather than each network device performing discrete backups.

Satisfies: SRG-APP-000516-NDM-000340, SRG-APP-000516-NDM-000341

Check

Verify system settings-backup weekly and continuous are set to true and a server is configured with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "show running-config system settings-backup". 4. Check Weekly Status. If system settings-backup weekly does not state "true", this is a finding. 5. Check Continuous Status. If system settings-backup continuous does not state "true", this is a finding. 6. Check Server Configuration. If there is no remote server configured, this is a finding.

Fix

Configure system settings-backup with a remote server and enable weekly backup with the following steps:

1. Log on to the SSH CLI. 2. Enter "enable" and provide the password. 3. Enter "configure terminal". 4. Enter "system settings-backup address [IPADDRESS]". (Replace [IPADDRESS] with the IPv4 or IPv6 address of the backup server.) 5. Enter "system settings-backup port PORT" and replace PORT with the TCP port number of the SCP backup server, e.g., 22. 6. Enter "system settings-backup file-path /PATH" and replace /PATH with the full-qualified filesystem path on the server. 7. Enter "system settings-backup use-proxy false" and replace false if the system must use a proxy to send the backup. 8. Enter "system settings-backup username USERNAME" and replace USERNAME with the username of the SCP backup server. 9. Enter "system settings-backup password", press "Enter", and type the password. 10. Enter "system settings-backup include-appliance-name true". 11. Enter "system settings-backup weekly true". 12. Enter "system settings-backup continuous true". 13. Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode.

Identifiers

Group ID
V-285606
Group title
SRG-APP-000516-NDM-000340
Rule ID
SV-285606r1274298_rule
Check ID
C-90286r1272935_chk
Fix ID
F-90191r1274297_fix