STIGQter STIGQter: STIG Summary: MS SQL Server 2016 Instance Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 23 Apr 2021:

When updates are applied to SQL Server software, any software components that have been replaced or made unnecessary must be removed.

DISA Rule

SV-213993r617437_rule

Vulnerability Number

V-213993

Group Title

SRG-APP-000454-DB-000389

Rule Version

SQL6-D0-012700

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove all features that are not required.

Check Contents

From the server documentation, obtain a listing of required components.

Generate a listing of components installed on the server.

Click Start >> Type "SQL Server 2016 Installation Center" >> Launch the program >> Click Tools >> Click "Installed SQL Server features discovery report"

Compare the feature listing against the required components listing. If any features are installed, but are not required, this is a finding.

Vulnerability Number

V-213993

Documentable

False

Rule Version

SQL6-D0-012700

Severity Override Guidance

From the server documentation, obtain a listing of required components.

Generate a listing of components installed on the server.

Click Start >> Type "SQL Server 2016 Installation Center" >> Launch the program >> Click Tools >> Click "Installed SQL Server features discovery report"

Compare the feature listing against the required components listing. If any features are installed, but are not required, this is a finding.

Check Content Reference

M

Target Key

3993

Comments