STIGQter STIGQter: STIG Summary: MS SQL Server 2014 Instance Security Technical Implementation Guide Version: 1 Release: 10 Benchmark Date: 24 Apr 2020:

SQL Server must have the Client Tools SDK software component removed if it is unused.

DISA Rule

SV-82335r1_rule

Vulnerability Number

V-67845

Group Title

SRG-APP-000141-DB-000091

Rule Version

SQL4-00-016845

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Either using the Start menu or via the command "control.exe", open the Windows Control Panel. Open Programs and Features. Double-click on Microsoft SQL Server 2014. In the dialog box that appears, select Remove. Wait for the Remove wizard to appear.

Select '<< Remove shared features only >>'; click Next. Note: all SQL Server 2014 instances will be affected by this action.)

Select Client Tools Software Development Kit; click Next.

Follow the remaining prompts, to remove the Client Tools Software Development Kit from SQL Server.

Check Contents

If the Client Tools Software Development Kit is used and satisfies organizational requirements, this is not a finding.

Either using the Start menu or via the command "control.exe", open the Windows Control Panel. Open Programs and Features. Double-click on Microsoft SQL Server 2014. In the dialog box that appears, select Remove. Wait for the Remove wizard to appear.

Select '<< Remove shared features only >>'; click Next.

If the list of shared features includes Client Tools SDK, this is a finding.

Vulnerability Number

V-67845

Documentable

False

Rule Version

SQL4-00-016845

Severity Override Guidance

If the Client Tools Software Development Kit is used and satisfies organizational requirements, this is not a finding.

Either using the Start menu or via the command "control.exe", open the Windows Control Panel. Open Programs and Features. Double-click on Microsoft SQL Server 2014. In the dialog box that appears, select Remove. Wait for the Remove wizard to appear.

Select '<< Remove shared features only >>'; click Next.

If the list of shared features includes Client Tools SDK, this is a finding.

Check Content Reference

M

Target Key

2639

Comments