STIGQter STIGQter: STIG Summary:

MS SQL Server 2016 Instance Security Technical Implementation Guide

Version: 3

Release: 6 Benchmark Date: 05 Jan 2026

CheckedNameTitle
SV-213929r1018580_ruleSQL Server must limit the number of concurrent sessions to an organization-defined number per user for all accounts and/or account types.
SV-213930r1043176_ruleSQL Server must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.
SV-213931r1043176_ruleSQL Server must be configured to utilize the most-secure authentication method available.
SV-213932r1137654_ruleSQL Server must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
SV-213933r1167475_ruleSQL Server must protect against a user falsely repudiating by ensuring all accounts are individual, unique, and not shared.
SV-213934r960864_ruleSQL Server must protect against a user falsely repudiating by ensuring the NT AUTHORITY SYSTEM account is not used for administration.
SV-213935r960864_ruleSQL Server must protect against a user falsely repudiating by ensuring only clearly unique Active Directory user accounts can connect to the instance.
SV-213936r960879_ruleSQL Server must be configured to generate audit records for DoD-defined auditable events within all DBMS/database components.
SV-213937r960882_ruleSQL Server must allow only the ISSM (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
SV-213939r1167477_ruleSQL Server must generate audit records when attempts to access privileges, categorized information, and security objects occur.
SV-213940r960888_ruleSQL Server must initiate session auditing upon startup.
SV-213941r960909_ruleSQL Server must include additional, more detailed, organization-defined information in the audit records for audit events identified by type, location, or subject.
SV-213942r1043188_ruleSQL Server must by default shut down upon audit failure, to include the unavailability of space for more audit log records; or must be configurable to shut down upon audit failure.
SV-213943r1043188_ruleSQL Server must be configurable to overwrite audit log records, oldest first (First-In-First-Out - FIFO), in the event of unavailability of space for more audit log records.
SV-213944r960930_ruleThe audit information produced by SQL Server must be protected from unauthorized access, modification, and deletion.
SV-213948r960942_ruleSQL Server must protect its audit configuration from authorized and unauthorized access and modification.
SV-213950r960960_ruleSQL Server must limit privileges to change software modules and links to software external to SQL Server.
SV-213951r960960_ruleSQL Server must limit privileges to change software modules, to include stored procedures, functions and triggers, and links to software external to SQL Server.
SV-213952r960960_ruleSQL Server software installation account must be restricted to authorized users.
SV-213953r960960_ruleDatabase software, including DBMS configuration files, must be stored in dedicated directories, separate from the host OS and other applications.
SV-213954r960963_ruleDefault demonstration and sample databases, database objects, and applications must be removed.
SV-213955r960963_ruleUnused database components, DBMS software, and database objects must be removed.
SV-213956r960963_ruleUnused database components that are integrated in SQL Server and cannot be uninstalled must be disabled.
SV-213957r960963_ruleAccess to xp_cmdshell must be disabled, unless specifically required and approved.
SV-213958r960963_ruleAccess to CLR code must be disabled or restricted, unless specifically required and approved.
SV-213959r960963_ruleAccess to Non-Standard extended stored procedures must be disabled or restricted, unless specifically required and approved.
SV-213960r1018585_ruleAccess to linked servers must be disabled or restricted, unless specifically required and approved.
SV-213961r1167480_ruleSQL Server must be configured to prohibit or restrict the use of organization-defined protocols as defined in the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and vulnerability assessments.
SV-213964r1112499_ruleIf DBMS authentication using passwords is employed, SQL Server must enforce the DOD standards for password complexity and lifetime.
SV-213965r1018610_ruleContained databases must use Windows principals.
SV-213966r1051304_ruleIf passwords are used for authentication, SQL Server must transmit only encrypted representations of passwords.
SV-213967r961029_ruleConfidentiality of information during transmission is controlled through the use of an approved TLS version.
SV-213968r961041_ruleSQL Server must enforce authorized access to all PKI private keys stored/utilized by SQL Server.
SV-213969r1167483_ruleSQL Server must use NIST FIPS 140-2/140-3-validated cryptographic operations for encryption, hashing, and signing.
SV-213970r961053_ruleSQL Server must uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users).
SV-213972r961128_ruleSQL Server must protect the confidentiality and integrity of all information at rest.
SV-213973r961128_ruleThe Service Master Key must be backed up and stored in a secure location that is not on the SQL Server.
SV-213974r961128_ruleThe Master Key must be backed up and stored in a secure location that is not on the SQL Server.
SV-213975r1137657_ruleSQL Server must prevent unauthorized and unintended information transfer via shared system resources.
SV-213976r1137657_ruleSQL Server must prevent unauthorized and unintended information transfer via Instant File Initialization (IFI).
SV-213977r1137658_ruleAccess to database files must be limited to relevant processes and to authorized, administrative users.
SV-213978r1067807_ruleSQL Server must reveal detailed error messages only to documented and approved individuals or roles.
SV-213979r961353_ruleSQL Server must prevent non-privileged users from executing privileged functions, to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
SV-213980r961359_ruleUse of credentials and proxies must be restricted to necessary cases only.
SV-213983r1018595_ruleSQL Server must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
SV-213984r961398_ruleSQL Server must provide a warning to appropriate support staff when allocated audit record storage volume reaches 75% of maximum audit record storage capacity.
SV-213985r961401_ruleSQL Server must provide an immediate real-time alert to appropriate support staff of all audit log failures.
SV-213986r961443_ruleSQL Server must record time stamps in audit records and application data that can be mapped to Coordinated Universal Time (UTC, formerly GMT).
SV-213987r961461_ruleSQL Server must enforce access restrictions associated with changes to the configuration of the instance.
SV-213988r961461_ruleWindows must enforce access restrictions associated with changes to the configuration of the SQL Server instance.
SV-213989r1167485_ruleSQL Server must produce audit records when attempts to modify SQL Server configuration and privileges occur within the database(s).
SV-213991r1137659_ruleSQL Server must maintain a separate execution domain for each executing process.
SV-213992r1137659_ruleSQL Server services must be configured to run under unique dedicated user accounts.
SV-213993r961677_ruleWhen updates are applied to SQL Server software, any software components that have been replaced or made unnecessary must be removed.
SV-213994r1137667_ruleSecurity-relevant software updates to SQL Server must be installed within the time period directed by an authoritative source (e.g. IAVM, CTOs, DTMs, and STIGs).
SV-214000r961800_ruleSQL Server must generate audit records when successful and unsuccessful attempts to add privileges/permissions occur.
SV-214002r961800_ruleSQL Server must generate audit records when successful and unsuccessful attempts to modify privileges/permissions occur.
SV-214004r1167486_ruleSQL Server must generate audit records when successful and unsuccessful attempts to modify security objects occur.
SV-214008r961812_ruleSQL Server must generate audit records when successful and unsuccessful attempts to delete privileges/permissions occur.
SV-214014r1167488_ruleSQL Server must generate audit records when successful and unsuccessful logons or connection attempts occur.
SV-214021r961839_ruleSQL Server must generate audit records for all direct access to the database(s).
SV-214025r961860_ruleThe system SQL Server must off-load audit data to a separate log management facility; this must be continuous and in near real time for systems with a network connection to the storage facility and weekly or more often for stand-alone systems.
SV-214026r961863_ruleSQL Server must configure Customer Feedback and Error Reporting.
SV-214027r961863_ruleSQL Server must configure SQL Server Usage and Error Reporting Auditing.
SV-214028r1137654_ruleThe SQL Server default account [sa] must be disabled.
SV-214029r960963_ruleSQL Server default account [sa] must have its name changed.
SV-214030r961359_ruleExecution of startup stored procedures must be restricted to necessary cases only.
SV-214031r961863_ruleSQL Server Mirroring endpoint must utilize AES encryption.
SV-214032r961863_ruleSQL Server Service Broker endpoint must utilize AES encryption.
SV-214033r960963_ruleSQL Server execute permissions to access the registry must be revoked, unless specifically required and approved.
SV-214034r960963_ruleFilestream must be disabled, unless specifically required and approved.
SV-214035r960963_ruleOle Automation Procedures feature must be disabled, unless specifically required and approved.
SV-214036r960963_ruleSQL Server User Options feature must be disabled, unless specifically required and approved.
SV-214037r960963_ruleRemote Access feature must be disabled, unless specifically required and approved.
SV-214038r960963_ruleHadoop Connectivity feature must be disabled, unless specifically required and approved.
SV-214039r960963_ruleAllow Polybase Export feature must be disabled, unless specifically required and approved.
SV-214040r960963_ruleRemote Data Archive feature must be disabled, unless specifically required and approved.
SV-214041r960963_ruleSQL Server External Scripts Enabled feature must be disabled, unless specifically required and approved.
SV-214042r961863_ruleThe SQL Server Browser service must be disabled unless specifically required and approved.
SV-214043r960963_ruleSQL Server Replication Xps feature must be disabled, unless specifically required and approved.
SV-214044r961863_ruleIf the SQL Server Browser Service is specifically required and approved, SQL instances must be hidden.
SV-214045r961047_ruleWhen using command-line tools such as SQLCMD in a mixed-mode authentication environment, users must use a logon method that does not expose the password.
SV-214046r961047_ruleApplications must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.
SV-265870r1138543_ruleMicrosoft SQL Server products must be a version supported by the vendor.