Skip to main content

Database / Relational / Controls / DEV

Access Control for Backup and Restore Operations

CCC.RDMS.CN04 · Access

Restrict who can initiate, manage, and validate database backup or restore operations through strict role-based or least-privilege access. Prevents accidental or malicious restorations, protecting data integrity and availability.

Related Capabilities

IDTitleDescription
CCC.Core.CP11BackupThe service can generate copies of its data or configurations in the form of automated backups, snapshot-based backups, or incremental backups.

Related Threats

IDTitleDescription
CCC.RDMS.TH04Unintentional Database Backup RestorationA database backup may be restored unintentionally, potentially leading to the loss or overwrite of current data. This condition could disrupt operations and result in data inconsistency or corruption.

Assessment Requirements

IDTextApplicability
CCC.RDMS.CN04.AR01When there is an attempt to perform a backup or restore, then the attempt must fail with an access denied message if credentials or roles that are not explicitly authorized for backup/restore functions.tlp-red, tlp-amber

Guideline Mappings

FrameworkIDRemarks
NIST-CSFPR.AC-4
NIST_800_53AC-6