STIGQter STIGQter: STIG Summary: MS SQL Server 2016 Instance Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 23 Apr 2021:

SQL Server must prevent unauthorized and unintended information transfer via shared system resources.

DISA Rule

SV-213976r617437_rule

Vulnerability Number

V-213976

Group Title

SRG-APP-000243-DB-000373

Rule Version

SQL6-D0-009900

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If IFI is not documented as being required, disable instant file initialization for the instance of SQL Server by removing the SQL Service SID and/or service account from the "Perform volume maintenance tasks" Local Rights Assignment.

Check Contents

Review the system documentation to determine if Instant File Initialization (IFI) is required.

If IFI is documented as required, this is not a finding.

Review system configuration to determine whether IFI support has been enabled (by default in SQL Server 2016).

Start >> Control Panel >> Administrative Tools >> Local Security Policy >> Local Policies >> User Rights Assignment

If the SQL Service SID (Default instance: NT SERVICE\MSSQLSERVER. Named instance: NT SERVICE\MSSQL$InstanceName) has been granted "Perform volume maintenance tasks" Local Rights Assignment and if it is not documented in the system documentation, this is a finding.

Vulnerability Number

V-213976

Documentable

False

Rule Version

SQL6-D0-009900

Severity Override Guidance

Review the system documentation to determine if Instant File Initialization (IFI) is required.

If IFI is documented as required, this is not a finding.

Review system configuration to determine whether IFI support has been enabled (by default in SQL Server 2016).

Start >> Control Panel >> Administrative Tools >> Local Security Policy >> Local Policies >> User Rights Assignment

If the SQL Service SID (Default instance: NT SERVICE\MSSQLSERVER. Named instance: NT SERVICE\MSSQL$InstanceName) has been granted "Perform volume maintenance tasks" Local Rights Assignment and if it is not documented in the system documentation, this is a finding.

Check Content Reference

M

Target Key

3993

Comments