SV-251185r960792_rule
V-251185
SRG-APP-000033-DB-000084
RD6X-00-000800
CAT I
10
To modify the commands or keys a user is able to access, perform the following steps:
1. Log in to Redis Enterprise.
2. Navigate to the access controls tab.
3. Ensure the appropriate role is configured by inspecting the Redis ACL rules and Roles in the Redis ACL and Role sub-tabs.
4. If an appropriate role is not present, create the appropriate role.
5. On the users tab, assign the appropriate role to the user in question.
Review the system documentation to determine if accounts have been set with appropriate, organizationally defined role-based permissions. Compare these settings with the settings on the actual DB.
To find the database id, run the command:
rladmin status extra all.
1. Log in to Redis Enterprise.
2. Navigate to the access controls tab.
3. Verify that each user is assigned an appropriate role.
If a user is not assigned an appropriate role, this is a finding.
If the appropriate role is not assigned to a user, or the roles and permission settings are not documented, this is a finding.
V-251185
False
RD6X-00-000800
Review the system documentation to determine if accounts have been set with appropriate, organizationally defined role-based permissions. Compare these settings with the settings on the actual DB.
To find the database id, run the command:
rladmin status extra all.
1. Log in to Redis Enterprise.
2. Navigate to the access controls tab.
3. Verify that each user is assigned an appropriate role.
If a user is not assigned an appropriate role, this is a finding.
If the appropriate role is not assigned to a user, or the roles and permission settings are not documented, this is a finding.
M
5443