SV-220359r960960_rule
V-220359
SRG-APP-000133-DB-000362
ML09-00-002900
CAT II
10
Revoke unauthorized memberships in the MarkLogic modification group(s)/role(s).
Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Users. For users who are not authorized to own database objects, remove the users.
Identify the group(s)/role(s) established for MarkLogic modification and the list of users in those group(s)/roles.
Identify the individuals authorized to modify the DBMS.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Users. If there is a User who is not authorized to own database objects, this is a finding.
V-220359
False
ML09-00-002900
Identify the group(s)/role(s) established for MarkLogic modification and the list of users in those group(s)/roles.
Identify the individuals authorized to modify the DBMS.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Users. If there is a User who is not authorized to own database objects, this is a finding.
M
4064