SV-206520r617447_rule
V-206520
SRG-APP-000023
SRG-APP-000023-DB-000001
CAT II
10
Integrate DBMS security with an organization-level authentication/access mechanism providing account management for all users, groups, roles, and any other principals.
For each DBMS-managed account that is not documented and approved, either transfer it to management by the external mechanism, or document the need for it and obtain approval, as appropriate.
If all accounts are authenticated by the organization-level authentication/access mechanism and not by the DBMS, this is not a finding.
If there are any accounts managed by the DBMS, review the system documentation for justification and approval of these accounts.
If any DBMS-managed accounts exist that are not documented and approved, this is a finding.
V-206520
False
SRG-APP-000023-DB-000001
If all accounts are authenticated by the organization-level authentication/access mechanism and not by the DBMS, this is not a finding.
If there are any accounts managed by the DBMS, review the system documentation for justification and approval of these accounts.
If any DBMS-managed accounts exist that are not documented and approved, this is a finding.
M
2902