SV-206526r617447_rule
V-206526
SRG-APP-000091
SRG-APP-000091-DB-000325
CAT II
10
Deploy a DBMS capable of producing the required audit records when it denies or fails to complete access to privileges/permissions/role membership.
If currently required, configure the DBMS to produce audit records when it denies access to privileges/permissions/role membership.
Configure the DBMS to produce audit records when other errors prevent access to privileges/permissions/role membership.
Review DBMS documentation to verify that audit records can be produced when the system denies or fails to complete attempts to retrieve privileges/permissions/role membership.
If the DBMS is not capable of this, this is a finding.
If the DBMS is currently required to audit the retrieval of privilege/permission/role membership information, review the DBMS/database security and audit configurations to verify that audit records are produced when the DBMS denies retrieval of privileges/permissions/role memberships.
If they are not produced, this is a finding.
Review the DBMS/database security and audit configurations to verify that audit records are produced when other errors prevent retrieval of privileges/permissions/role memberships.
If they are not produced, this is a finding.
V-206526
False
SRG-APP-000091-DB-000325
Review DBMS documentation to verify that audit records can be produced when the system denies or fails to complete attempts to retrieve privileges/permissions/role membership.
If the DBMS is not capable of this, this is a finding.
If the DBMS is currently required to audit the retrieval of privilege/permission/role membership information, review the DBMS/database security and audit configurations to verify that audit records are produced when the DBMS denies retrieval of privileges/permissions/role memberships.
If they are not produced, this is a finding.
Review the DBMS/database security and audit configurations to verify that audit records are produced when other errors prevent retrieval of privileges/permissions/role memberships.
If they are not produced, this is a finding.
M
2902