SV-206596r617447_rule
V-206596
SRG-APP-000378
SRG-APP-000378-DB-000365
CAT II
10
Document and obtain approval for any non-administrative users who require the ability to create, alter or replace logic modules.
Implement the approved permissions. Revoke any unapproved permissions.
If the DBMS supports only software development, experimentation and/or developer-level testing (that is, excluding production systems, integration testing, stress testing, and user acceptance testing), this is not a finding.
Review the DBMS and database security settings with respect to non-administrative users' ability to create, alter, or replace logic modules, to include but not necessarily only stored procedures, functions, triggers, and views.
If any such permissions exist and are not documented and approved, this is a finding.
V-206596
False
SRG-APP-000378-DB-000365
If the DBMS supports only software development, experimentation and/or developer-level testing (that is, excluding production systems, integration testing, stress testing, and user acceptance testing), this is not a finding.
Review the DBMS and database security settings with respect to non-administrative users' ability to create, alter, or replace logic modules, to include but not necessarily only stored procedures, functions, triggers, and views.
If any such permissions exist and are not documented and approved, this is a finding.
M
2902