STIGQter STIGQter: STIG Summary: Microsoft Azure SQL Database Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

Azure SQL Database must associate organization-defined types of security labels having organization-defined security label values with information in storage.

DISA Rule

SV-255313r961269_rule

Vulnerability Number

V-255313

Group Title

SRG-APP-000311-DB-000308

Rule Version

ASQL-00-002500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Deploy SQL Information Protection (see link below) or Azure SQL Database Row-Level Security (see link below), a third-party software, or add custom data structures, data elements and application code to provide reliable security labeling of information in storage.

https://docs.microsoft.com/en-us/azure/security-center/security-center-info-protection-policy?
https://msdn.microsoft.com/en-us/library/dn765131.aspx

Check Contents

If security labeling is not required, this is not a finding.

If security labeling requirements have been specified, but a third-party solution, SQL Information Protection, or an Azure SQL Database Row-Level security solution is implemented that reliably maintains labels on information in storage, this is a finding.

Vulnerability Number

V-255313

Documentable

False

Rule Version

ASQL-00-002500

Severity Override Guidance

If security labeling is not required, this is not a finding.

If security labeling requirements have been specified, but a third-party solution, SQL Information Protection, or an Azure SQL Database Row-Level security solution is implemented that reliably maintains labels on information in storage, this is a finding.

Check Content Reference

M

Target Key

5500