STIGQter STIGQter: STIG Summary: Microsoft SQL Server 2022 Database Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Apr 2026:

SQL Server must associate organization-defined types of security labels having organization-defined security label values with information in process, transit, or storage.

DISA Rule

SV-271184r1138541_rule

Vulnerability Number

V-271184

Group Title

SRG-APP-000313-DB-000309

Rule Version

SQLD-22-002600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Deploy SQL Server Row-Level Security (refer to link below) or a third-party software, or add custom data structures, data elements, and application code, to provide reliable security labeling of information.

https://msdn.microsoft.com/en-us/library/dn765131.aspx

Check Contents

If security labeling is not required, this is not a finding.

If security labeling requirements have been specified, but neither a third-party solution nor a SQL Server Row-Level security solution is implemented that reliably maintains labels on information, this is a finding.

Vulnerability Number

V-271184

Documentable

False

Rule Version

SQLD-22-002600

Severity Override Guidance

If security labeling is not required, this is not a finding.

If security labeling requirements have been specified, but neither a third-party solution nor a SQL Server Row-Level security solution is implemented that reliably maintains labels on information, this is a finding.

Check Content Reference

M

Target Key

5676