SV-271284r1109111_rule
V-271284
SRG-APP-000133-DB-000179
SQLI-22-006600
CAT II
10
Implement and document a process by which changes made to software libraries are monitored and alerted. A PowerShell based hashing solution is one such process. The Get-FileHash command can be used to compute the SHA-2 hash of one or more files. For more information, refer to the following link:
https://msdn.microsoft.com/en-us/powershell/reference/5.1/microsoft.powershell.utility/get-filehash
Using the Export-Clixml command, a baseline can be established and exported to a file:
https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/export-clixml?view=powershell-7.5
Using the Compare-Object command, a comparison of the latest baseline versus the original baseline can expose the differences:
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-powershell-1.0/ee156812(v=technet.10)?redirectedfrom=MSDN
Review server documentation to determine the process by which shared software libraries are monitored for change. Ensure the process alerts for changes in a file's ownership, modification dates, and hash value at a minimum.
If alerts do not at least hash their value, this is a finding.
To determine the location for these instance-specific binaries:
1. Launch SQL Server Management Studio (SSMS).
2. Connect to the instance to be reviewed.
3. Right-click server name in Object Explorer.
4. Click "Facets".
5. Select the "Server" facet.
6. Record the value for the "RootDirectory" facet property.
Tip: Use the Get-FileHash cmdlet shipped with PowerShell 5.0 to get the SHA-2 hash of one or more files.
V-271284
False
SQLI-22-006600
Review server documentation to determine the process by which shared software libraries are monitored for change. Ensure the process alerts for changes in a file's ownership, modification dates, and hash value at a minimum.
If alerts do not at least hash their value, this is a finding.
To determine the location for these instance-specific binaries:
1. Launch SQL Server Management Studio (SSMS).
2. Connect to the instance to be reviewed.
3. Right-click server name in Object Explorer.
4. Click "Facets".
5. Select the "Server" facet.
6. Record the value for the "RootDirectory" facet property.
Tip: Use the Get-FileHash cmdlet shipped with PowerShell 5.0 to get the SHA-2 hash of one or more files.
M
5677