Skip to main content

Storage / File Storage / Controls / DEV

Restrict Snapshot Access for File Systems

CCC.FileStor.CN05 · Data

Ensure that backup snapshots and replicas of the file system are not more accessible than the primary file system.

Related Capabilities

IDTitleDescription
CCC.FileStor.CP07Multi-Availability-Zone DurabilityThe service can replicate file system data across multiple availability zones within a region to improve availability during zone failures.
CCC.Core.CP08Data ReplicationThe service automatically replicates data across multiple deployments simultaneously with parity, or may be configured to do so.
CCC.Core.CP11BackupThe service can generate copies of its data or configurations in the form of automated backups, snapshot-based backups, or incremental backups.
CCC.Core.CP12RecoveryThe service can be reverted to a previous state by providing a compatible backup or snapshot identifier.

Related Threats

IDTitleDescription
CCC.FileStor.TH05Snapshots or Replicas Expose File System ContentsBackup snapshots, replicas, or cross-region copies of the file system may be configured with access controls broader than the primary mount. Unauthorized users or external systems can read file content from the copy without mounting the live file system. This impacts confidentiality of data retained in snapshots and replicas.

Assessment Requirements

IDTextApplicability
CCC.FileStor.CN05.AR01When a snapshot or replica of the file system is created, the service MUST apply access controls that are equivalent to or stricter than those on the primary file system.tlp-clear, tlp-green, tlp-amber, tlp-red