SV-271270r1108426_rule
V-271270
SRG-APP-000089-DB-000064
SQLI-22-004300
CAT II
10
Add all required audit events to the STIG-compliant audit specification server documentation.
Review the server documentation to determine if any additional events are required to be audited. If no additional events are required, this is not a finding.
Execute the following to get all of the installed audits:
SELECT name AS 'Audit Name',
status_desc AS 'Audit Status',
audit_file_path AS 'Current Audit File'
FROM sys.dm_server_audit_status
All currently defined audits for the SQL server instance will be listed. If no audits are returned, this is a finding.
To view the actions being audited by the audits, execute the following:
SELECT a.name AS 'AuditName',
s.name AS 'SpecName',
d.audit_action_name AS 'ActionName',
d.audited_result AS 'Result'
FROM sys.server_audit_specifications s
JOIN sys.server_audits a ON s.audit_guid = a.audit_guid
JOIN sys.server_audit_specification_details d ON s.server_specification_id = d.server_specification_id
WHERE a.is_state_enabled = 1
Compare the documentation to the list of generated audit events. If there are any missing events, this is a finding.
V-271270
False
SQLI-22-004300
Review the server documentation to determine if any additional events are required to be audited. If no additional events are required, this is not a finding.
Execute the following to get all of the installed audits:
SELECT name AS 'Audit Name',
status_desc AS 'Audit Status',
audit_file_path AS 'Current Audit File'
FROM sys.dm_server_audit_status
All currently defined audits for the SQL server instance will be listed. If no audits are returned, this is a finding.
To view the actions being audited by the audits, execute the following:
SELECT a.name AS 'AuditName',
s.name AS 'SpecName',
d.audit_action_name AS 'ActionName',
d.audited_result AS 'Result'
FROM sys.server_audit_specifications s
JOIN sys.server_audits a ON s.audit_guid = a.audit_guid
JOIN sys.server_audit_specification_details d ON s.server_specification_id = d.server_specification_id
WHERE a.is_state_enabled = 1
Compare the documentation to the list of generated audit events. If there are any missing events, this is a finding.
M
5677