SV-82375r1_rule
V-67885
SRG-APP-000340-DB-000304
SQL4-00-032500
CAT II
10
Use REVOKE and/or DENY and/or ALTER SERVER ROLE ... DROP MEMBER ... statements to align EXECUTE permissions (and any other relevant permissions) with documented requirements.
Review the system documentation to obtain the definition of the SQL Server database/DBMS functionality considered privileged in the context of the system in question.
Review the SQL Server security configuration and/or other means used to protect privileged functionality from unauthorized use.
If the configuration does not protect all of the actions defined as privileged, this is a finding.
The database permission functions and views provided in the supplemental file Permissions.sql can help with this.
V-67885
False
SQL4-00-032500
Review the system documentation to obtain the definition of the SQL Server database/DBMS functionality considered privileged in the context of the system in question.
Review the SQL Server security configuration and/or other means used to protect privileged functionality from unauthorized use.
If the configuration does not protect all of the actions defined as privileged, this is a finding.
The database permission functions and views provided in the supplemental file Permissions.sql can help with this.
M
2639