Network Device Management Rules : Ensuring the system backs up configuration files
  
Ensuring the system backs up configuration files
Rule Title: RiOS must back up the system configuration files when configuration changes are made to the device.
STIG ID: RICX-DM-000100
Rule ID: SV-77441r1_rule Severity: CAT II
Vuln ID: V-62951 Class: Unclass
Information system backup is a critical step in maintaining data assurance and availability. Information system and security-related documentation contains information pertaining to system configuration and security settings. If this information were not backed up, and a system failure were to occur, the security settings would be difficult to reconfigure quickly and accurately. Maintaining a backup of information system and security-related documentation provides for a quicker recovery time when system outages occur.
This control requires the network device to support the organizational central backup process for user account information associated with the network device. This function might be provided by the network device itself; however, the preferred best practice is a centralized backup rather than each network device performing discrete backups.
Verifying the system backs up configuration files
Verify that RiOS is backed up when system configuration changes are made to the device by interviewing the site representative and checking any existing backup log. Evidence might also be provided by the date of the last back up.
1. Connect to the Management Console.
2. Choose Administration > Configurations to display the Configurations page.
3. Verify that the table for Configuration and Date contains backup configurations. If there are no entries under Configuration and Date, this is a security vulnerability finding.
Configuring the system to back up configuration files
When changes are made to the system configuration, use the following procedure for backing up the device.
1. Connect to the Management Console.
2. Choose Administration > System Settings: Configurations to display the Configurations page.
3. Set the value of New Configuration Name to the naming standards for the organization backups.
4. Click Save.
5. Under Configurations, verify that the saved configuration is listed with the current date and time.