STIGQter STIGQter: STIG Summary: MS SQL Server 2016 Instance Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 23 Apr 2021:

SQL Server must include additional, more detailed, organization-defined information in the audit records for audit events identified by type, location, or subject.

DISA Rule

SV-213941r617437_rule

Vulnerability Number

V-213941

Group Title

SRG-APP-000101-DB-000044

Rule Version

SQL6-D0-005500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Design and deploy an Audit that captures all auditable events and data items. In the event a third-party tool is used for auditing it must contain all the required information including but not limited to events, type, location, subject, date and time and by whom the change occurred.

Implement additional custom audits to capture the additional organizational required information.

Check Contents

If a SQL Server Audit is not in use for audit purposes, this is a finding unless a third-party product is being used that can perform detailed auditing for SQL Server.

Review system documentation to determine whether SQL Server is required to audit any events, and any fields, in addition to those in the standard audit.

If there are none specified, this is not a finding.

If SQL Server Audit is in use, compare the audit specification(s) with the documented requirements.

If any such requirement is not satisfied by the audit specification(s) (or by supplemental, locally-deployed mechanisms), this is a finding.

Vulnerability Number

V-213941

Documentable

False

Rule Version

SQL6-D0-005500

Severity Override Guidance

If a SQL Server Audit is not in use for audit purposes, this is a finding unless a third-party product is being used that can perform detailed auditing for SQL Server.

Review system documentation to determine whether SQL Server is required to audit any events, and any fields, in addition to those in the standard audit.

If there are none specified, this is not a finding.

If SQL Server Audit is in use, compare the audit specification(s) with the documented requirements.

If any such requirement is not satisfied by the audit specification(s) (or by supplemental, locally-deployed mechanisms), this is a finding.

Check Content Reference

M

Target Key

3993

Comments