SV-271370r1111091_rule
V-271370
SRG-APP-000496-DB-000334
SQLI-22-013800
CAT II
10
Add the required events to the server audit specification to audit denied actions.
Refer to the supplemental file "SQL2022Audit.sql" script.
Reference: https://learn.microsoft.com/en-us/sql/relational-databases/security/auditing/sql-server-audit-database-engine?
Review the SQL configuration to verify that audit records are produced when denied actions occur.
To determine if an audit is configured, execute the following script:
SELECT name AS 'Audit Name',
status_desc AS 'Audit Status',
audit_file_path AS 'Current Audit File'
FROM sys.dm_server_audit_status
If no records are returned, this is a finding.
Execute the following to verify the events below are included in the server audit specification:
SCHEMA_OBJECT_CHANGE_GROUP
SELECT a.name AS 'AuditName',
s.name AS 'SpecName',
d.audit_action_name AS 'ActionName',
d.audited_result AS 'Result'
FROM sys.server_audit_specifications s
JOIN sys.server_audits a ON s.audit_guid = a.audit_guid
JOIN sys.server_audit_specification_details d ON s.server_specification_id = d.server_specification_id
WHERE a.is_state_enabled = 1
AND d.audit_action_name IN (
'SCHEMA_OBJECT_CHANGE_GROUP'
)
Order by d.audit_action_name
If the identified groups are not returned, this is a finding.
V-271370
False
SQLI-22-013800
Review the SQL configuration to verify that audit records are produced when denied actions occur.
To determine if an audit is configured, execute the following script:
SELECT name AS 'Audit Name',
status_desc AS 'Audit Status',
audit_file_path AS 'Current Audit File'
FROM sys.dm_server_audit_status
If no records are returned, this is a finding.
Execute the following to verify the events below are included in the server audit specification:
SCHEMA_OBJECT_CHANGE_GROUP
SELECT a.name AS 'AuditName',
s.name AS 'SpecName',
d.audit_action_name AS 'ActionName',
d.audited_result AS 'Result'
FROM sys.server_audit_specifications s
JOIN sys.server_audits a ON s.audit_guid = a.audit_guid
JOIN sys.server_audit_specification_details d ON s.server_specification_id = d.server_specification_id
WHERE a.is_state_enabled = 1
AND d.audit_action_name IN (
'SCHEMA_OBJECT_CHANGE_GROUP'
)
Order by d.audit_action_name
If the identified groups are not returned, this is a finding.
M
5677