STIGQter STIGQter: STIG Summary: Database Security Requirements Guide Version: 4 Release: 5 Benchmark Date: 01 Apr 2026:

The DBMS must prevent the installation of organization-defined software and firmware components without verification that the component has been digitally signed using a certificate recognized and approved by the organization.

DISA Rule

SV-263606r981976_rule

Vulnerability Number

V-263606

Group Title

SRG-APP-000810

Rule Version

SRG-APP-000810-DB-000150

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the DBMS to prevent the installation of organization-defined software and firmware components without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization.

Check Contents

Verify the DBMS is configured to prevent the installation of organization-defined software and firmware components without verification that the component has been digitally signed using a certificate recognized and approved by the organization.

If the DBMS is not configured to prevent the installation of organization-defined software and firmware components without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization, this is a finding.

Vulnerability Number

V-263606

Documentable

False

Rule Version

SRG-APP-000810-DB-000150

Severity Override Guidance

Verify the DBMS is configured to prevent the installation of organization-defined software and firmware components without verification that the component has been digitally signed using a certificate recognized and approved by the organization.

If the DBMS is not configured to prevent the installation of organization-defined software and firmware components without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization, this is a finding.

Check Content Reference

M

Target Key

2902