STIGQter STIGQter: STIG Summary: Database Security Requirements Guide Version: 4 Release: 5 Benchmark Date: 01 Apr 2026:

The DBMS must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.

DISA Rule

SV-206600r1050788_rule

Vulnerability Number

V-206600

Group Title

SRG-APP-000389

Rule Version

SRG-APP-000389-DB-000372

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Modify and/or configure the DBMS and related applications and tools so that users are always required to reauthenticate when changing role or escalating privileges.

Modify and/or configure the DBMS and related applications and tools so that users are always required to reauthenticate when the specified cases needing reauthorization occur.

Check Contents

Review the system documentation and the configuration of the DBMS and related applications and tools.

If there are any circumstances under which a user is not required to reauthenticate when changing role or escalating privileges, this is a finding.

If the information owner has identified additional cases where reauthentication is needed, but there are circumstances where the system does not ask the user to reauthenticate when those cases occur, this is a finding.

Vulnerability Number

V-206600

Documentable

False

Rule Version

SRG-APP-000389-DB-000372

Severity Override Guidance

Review the system documentation and the configuration of the DBMS and related applications and tools.

If there are any circumstances under which a user is not required to reauthenticate when changing role or escalating privileges, this is a finding.

If the information owner has identified additional cases where reauthentication is needed, but there are circumstances where the system does not ask the user to reauthenticate when those cases occur, this is a finding.

Check Content Reference

M

Target Key

2902