STIGQter STIGQter: STIG Summary: Redis Enterprise 6.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

Redis Enterprise DBMS must enforce discretionary access control policies, as defined by the data owner, over defined subjects and objects.

DISA Rule

SV-251186r961317_rule

Vulnerability Number

V-251186

Group Title

SRG-APP-000328-DB-000301

Rule Version

RD6X-00-000900

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To assign a user to a role:
1. Log in to Redis Enterprise as an admin user.
2. Navigate to the access controls tab.
3. Ensure that each user is assigned a role according to organizationally defined policy.

To configure a Redis ACL rule that can be assigned to a user role:
1. Navigate to access control >> redis acls.
2. Edit an existing Redis ACL by hovering over a Redis ACL and clicking "Edit".
3. Create a new Redis ACL by clicking "Add".
4. Enter a descriptive name for the Redis ACL. This will be used to reference the ACL rule to the role.
5. Define the ACL rule.
6. Click "Save".

For more information:
https://docs.redislabs.com/latest/rs/security/passwords-users-roles/

Check Contents

Redis Enterprise discretionary access control is configured through the use of individual roles. Verify that enforcement of role-based access control (RBAC) is implemented.

Review the system documentation to determine if accounts have been set with appropriate, organizationally defined Discretionary Access Control permissions. Compare these settings with the settings on the actual DB.

1. Log in to Redis Enterprise.
2. Navigate to the access controls tab.
3. Verify that each user is assigned a role. If a user is not assigned an appropriate role, this is a finding.

If the appropriate access is not assigned to a user, or the access and permission settings are not documented, this is a finding.

Vulnerability Number

V-251186

Documentable

False

Rule Version

RD6X-00-000900

Severity Override Guidance

Redis Enterprise discretionary access control is configured through the use of individual roles. Verify that enforcement of role-based access control (RBAC) is implemented.

Review the system documentation to determine if accounts have been set with appropriate, organizationally defined Discretionary Access Control permissions. Compare these settings with the settings on the actual DB.

1. Log in to Redis Enterprise.
2. Navigate to the access controls tab.
3. Verify that each user is assigned a role. If a user is not assigned an appropriate role, this is a finding.

If the appropriate access is not assigned to a user, or the access and permission settings are not documented, this is a finding.

Check Content Reference

M

Target Key

5443