STIGQter STIGQter: STIG Summary: Database Security Requirements Guide Version: 3 Release: 1 Benchmark Date: 22 Jan 2021:

The DBMS must generate audit records when privileges/permissions are deleted.

DISA Rule

SV-206624r617447_rule

Vulnerability Number

V-206624

Group Title

SRG-APP-000499

Rule Version

SRG-APP-000499-DB-000330

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Deploy a DBMS capable of producing the required audit records when privileges/permissions/role memberships are removed, revoked, or denied to any user or role.

Configure DBMS audit settings to generate an audit record when privileges/permissions/role memberships are removed, revoked, or denied to any user or role.

Check Contents

Review DBMS documentation to verify that audit records can be produced when privileges/permissions/role memberships are removed, revoked, or denied to any user or role.

If the DBMS is not capable of this, this is a finding.

Review the DBMS/database security and audit configurations to verify that audit records are produced when privileges/permissions/role memberships are removed, revoked, or denied to any user or role.

If they are not produced, this is a finding.

Vulnerability Number

V-206624

Documentable

False

Rule Version

SRG-APP-000499-DB-000330

Severity Override Guidance

Review DBMS documentation to verify that audit records can be produced when privileges/permissions/role memberships are removed, revoked, or denied to any user or role.

If the DBMS is not capable of this, this is a finding.

Review the DBMS/database security and audit configurations to verify that audit records are produced when privileges/permissions/role memberships are removed, revoked, or denied to any user or role.

If they are not produced, this is a finding.

Check Content Reference

M

Target Key

2902

Comments