STIGQter STIGQter: STIG Summary: MS SQL Server 2016 Instance Security Technical Implementation Guide Version: 1 Release: 8 Benchmark Date: 24 Jan 2020: Unused database components, DBMS software, and database objects must be removed.

DISA Rule

SV-93879r1_rule

Vulnerability Number

V-79173

Group Title

SRG-APP-000141-DB-000091

Rule Version

SQL6-D0-007000

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove all features that are not required.

Check Contents

From the server documentation, obtain a listing of required components.

Generate a listing of components installed on the server.

Click Start >> Type "SQL Server 2016 Installation Center" >> Launch the program >> Click Tools >> Click "Installed SQL Server features discovery report"

Compare the feature listing against the required components listing.

If any features are installed, but are not required, this is a finding.

Vulnerability Number

V-79173

Documentable

False

Rule Version

SQL6-D0-007000

Severity Override Guidance

From the server documentation, obtain a listing of required components.

Generate a listing of components installed on the server.

Click Start >> Type "SQL Server 2016 Installation Center" >> Launch the program >> Click Tools >> Click "Installed SQL Server features discovery report"

Compare the feature listing against the required components listing.

If any features are installed, but are not required, this is a finding.

Check Content Reference

M

Target Key

3219

Comments