STIGQter STIGQter: STIG Summary: MongoDB Enterprise Advanced 8.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

MongoDB must require users to be individually authenticated before granting access to the shared accounts or resources.

DISA Rule

SV-279399r1179524_rule

Vulnerability Number

V-279399

Group Title

SRG-APP-000815-DB-000160

Rule Version

MD8X-00-012800

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Enable authorization for MongoDB Enterprise.

Read the directions in the MongoDB documentation here:
https://www.mongodb.com/docs/v8.0/tutorial/configure-scram-client-authentication/

Create the user administrator.

Edit the MongoDB database configuration file (default location /etc/mongod.conf) to contain the following setting in the security section:

security:
authorization: enabled

Stop/start (restart) the mongod or mongos instance using this configuration.

Log on to MongoDB as an authorized user created by the user administrator and run the following command to verify the output is "true":

db.getSiblingDB("admin").runCommand({getCmdLineOpts: 1}).parsed.security.authorization

The output of this command must be "true".

Check Contents

Check the MongoDB configuration file (default location /etc/mongod.conf) for a section named "security".

If this section does not contain the subkey of "authorization" with a value of "enabled" as shown below, this is a finding.

security:
authorization: enabled

Vulnerability Number

V-279399

Documentable

False

Rule Version

MD8X-00-012800

Severity Override Guidance

Check the MongoDB configuration file (default location /etc/mongod.conf) for a section named "security".

If this section does not contain the subkey of "authorization" with a value of "enabled" as shown below, this is a finding.

security:
authorization: enabled

Check Content Reference

M

Target Key

5728