27.01.2014 Views

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

GUIDELINES ON SECURING PUBLIC WEB SERVERS<br />

• C<strong>on</strong>tractual<br />

• Accepted practices<br />

• Criticality of data to organizati<strong>on</strong><br />

Organizati<strong>on</strong>al guidelines and policies.<br />

Although each organizati<strong>on</strong>’s <strong>Web</strong> server backup policy will be different to reflect its particular<br />

envir<strong>on</strong>ment, it should address the following issues:<br />

Purpose of the policy<br />

Parties affected by the policy<br />

<strong>Web</strong> servers covered by the policy<br />

Definiti<strong>on</strong>s of key terms, especially legal and technical<br />

Detailed requirements from the legal, business, and organizati<strong>on</strong>’s perspective<br />

Required frequency of backups<br />

Procedures for ensuring data is properly retained and protected<br />

Procedures for ensuring data is properly destroyed or archived when no l<strong>on</strong>ger required<br />

Procedures for preserving informati<strong>on</strong> for Freedom of Informati<strong>on</strong> Act (FOIA) requests, legal<br />

investigati<strong>on</strong>s, and other such requests<br />

Resp<strong>on</strong>sibilities of those involved in data retenti<strong>on</strong>, protecti<strong>on</strong>, and destructi<strong>on</strong> activities<br />

Retenti<strong>on</strong> period for each type of informati<strong>on</strong> logged 76<br />

Specific duties of a central/organizati<strong>on</strong>al data backup team, if <strong>on</strong>e exists.<br />

Three primary types of backups exist: full, incremental, and differential. Full backups include the OS,<br />

applicati<strong>on</strong>s, and data stored <strong>on</strong> the <strong>Web</strong> server (i.e., an image of every piece of data stored <strong>on</strong> the <strong>Web</strong><br />

server hard drives). The advantage of a full backup is that it is easy to restore the entire <strong>Web</strong> server to the<br />

state (e.g., c<strong>on</strong>figurati<strong>on</strong>, patch level, data) it was in when the backup was performed. The disadvantage<br />

of full backups is that they take c<strong>on</strong>siderable time and resources to perform. Incremental backups reduce<br />

the impact of backups by backing up <strong>on</strong>ly data that has changed since the previous backup (either full or<br />

incremental).<br />

Differential backups reduce the number of backup sets that must be accessed to restore a c<strong>on</strong>figurati<strong>on</strong> by<br />

backing up all changed data since the last full backup. However, each differential backup increases as<br />

76<br />

Organizati<strong>on</strong>s should carefully c<strong>on</strong>sider the retenti<strong>on</strong> period for <strong>Web</strong> transacti<strong>on</strong> logs and other <strong>Web</strong> server-related records.<br />

Many organizati<strong>on</strong>s are subject to multiple sets of legal and regulatory requirements that can affect their retenti<strong>on</strong> of <strong>Web</strong><br />

records. The Nati<strong>on</strong>al Archives and Records Administrati<strong>on</strong> (NARA) has a <strong>Web</strong> site for Federal records management,<br />

which is located at http://www.archives.gov/records-mgmt/.<br />

9-6

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!