SV-235184r638812_rule
V-235184
SRG-APP-000314-DB-000310
MYS8-00-011000
CAT II
10
Deploy MySQL Views and Stored Procedures or a third-party software, or add custom data structures, data elements and application code, to provide reliable security labeling of information in storage.
If security labeling is not required, this is not a finding.
If security labeling requirements have been specified, check for a MySQL solution using views and Stored Procedures to implement a row-level security solution that reliably maintains labels on information in storage.
For data that have been labeled with a column indicating data is classified read-only, views can be created and secured via access privileges such that a user can only view the data that have a specific tag or tags (e.g., user [x] can only view records that are labeled with the tag of classified).
If a MySQL solution through the use of views and stored procedures or a third party solution does not exist, this is a finding.
V-235184
False
MYS8-00-011000
If security labeling is not required, this is not a finding.
If security labeling requirements have been specified, check for a MySQL solution using views and Stored Procedures to implement a row-level security solution that reliably maintains labels on information in storage.
For data that have been labeled with a column indicating data is classified read-only, views can be created and secured via access privileges such that a user can only view the data that have a specific tag or tags (e.g., user [x] can only view records that are labeled with the tag of classified).
If a MySQL solution through the use of views and stored procedures or a third party solution does not exist, this is a finding.
M
5277