| Checked | Name | Title |
|---|
| ☐ | SV-271263r1108405_rule | SQL Server must limit the number of concurrent sessions to an organization-defined number per user for all accounts and/or account types. |
| ☐ | SV-271264r1111061_rule | SQL Server must be configured to use the most-secure authentication method available. |
| ☐ | SV-271265r1108933_rule | SQL Server must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals. |
| ☐ | SV-271266r1137654_rule | SQL Server must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies. |
| ☐ | SV-271267r1108417_rule | SQL Server must protect against a user falsely repudiating by ensuring only clearly unique Active Directory user accounts can connect to the instance. |
| ☐ | SV-271268r1136917_rule | SQL Server must protect against a user falsely repudiating by ensuring the NT AUTHORITY SYSTEM account is not used for administration. |
| ☐ | SV-271269r1108423_rule | SQL Server must protect against a user falsely repudiating by ensuring all accounts are individual, unique, and not shared. |
| ☐ | SV-271270r1108426_rule | SQL Server must be configured to generate audit records for DOD-defined auditable events within all DBMS/database components. |
| ☐ | SV-271271r1108429_rule | SQL Server must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited. |
| ☐ | SV-271272r1109110_rule | SQL Server must generate audit records when attempts to access privileges, categorized information, and security objects occur. |
| ☐ | SV-271273r1109234_rule | SQL Server must initiate session auditing upon startup. |
| ☐ | SV-271280r1108456_rule | SQL Server must include additional, more detailed, organization-defined information in the audit records for audit events identified by type, location, or subject. |
| ☐ | SV-271282r1109273_rule | The audit information produced by SQL Server must be protected from unauthorized access, modification, and deletion. |
| ☐ | SV-271283r1108465_rule | SQL Server must protect its audit configuration from authorized and unauthorized access and modification. |
| ☐ | SV-271284r1109111_rule | SQL Server must limit privileges to change software modules, to include stored procedures, functions and triggers, and links to software external to SQL Server. |
| ☐ | SV-271285r1109236_rule | SQL Server must limit privileges to change software modules and links to software external to SQL Server. |
| ☐ | SV-271286r1108474_rule | SQL Server software installation account must be restricted to authorized users. |
| ☐ | SV-271287r1108843_rule | Database software, including DBMS configuration files, must be stored in dedicated directories, separate from the host OS and other applications. |
| ☐ | SV-271290r1109112_rule | Default demonstration and sample databases, database objects, and applications must be removed. |
| ☐ | SV-271291r1108899_rule | Unused database components, DBMS software, and database objects must be removed. |
| ☐ | SV-271292r1111143_rule | The SQL Server Replication Xps feature must be disabled unless specifically required and approved. |
| ☐ | SV-271293r1111138_rule | The SQL Server External Scripts Enabled feature must be disabled, unless specifically required and approved. |
| ☐ | SV-271295r1111135_rule | The remote Data Archive feature must be disabled unless specifically required and approved. |
| ☐ | SV-271296r1111132_rule | The "Allow Polybase Export" feature must be disabled, unless specifically required and approved. |
| ☐ | SV-271297r1111129_rule | The "Hadoop Connectivity" feature must be disabled unless specifically required and approved. |
| ☐ | SV-271298r1111126_rule | The "Remote Access" feature must be disabled unless specifically required and approved. |
| ☐ | SV-271299r1108513_rule | Access to linked servers must be disabled or restricted, unless specifically required and approved. |
| ☐ | SV-271300r1109264_rule | Access to nonstandard, extended stored procedures must be disabled or restricted, unless specifically required and approved. |
| ☐ | SV-271301r1109114_rule | Access to common language runtime (CLR) code must be disabled or restricted unless specifically required and approved. |
| ☐ | SV-271302r1109113_rule | Access to xp_cmdshell must be disabled unless specifically required and approved. |
| ☐ | SV-271303r1109116_rule | SQL Server must be configured to prohibit or restrict the use of organization-defined ports, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and vulnerability assessments. |
| ☐ | SV-271304r1109265_rule | SQL Server must be configured to prohibit or restrict the use of organization-defined protocols as defined in the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and vulnerability assessments. |
| ☐ | SV-271305r1109239_rule | SQL Server must uniquely identify and authenticate users (or processes acting on behalf of organizational users). |
| ☐ | SV-271306r1109119_rule | Contained databases must use Windows principals. |
| ☐ | SV-271307r1109241_rule | If DBMS authentication using passwords is employed, SQL Server must enforce the DOD standards for password complexity and lifetime. |
| ☐ | SV-271309r1109243_rule | If passwords are used for authentication, SQL Server must transmit only encrypted representations of passwords. |
| ☐ | SV-271310r1111062_rule | Confidentiality of information during transmission must be controlled through the use of an approved TLS version. |
| ☐ | SV-271313r1111146_rule | When using command-line tools such as SQLCMD in a mixed-mode authentication environment, users must use a logon method that does not expose the password. |
| ☐ | SV-271314r1109121_rule | SQL Server must use NIST FIPS 140-2 or 140-3 validated cryptographic operations for encryption, hashing, and signing. |
| ☐ | SV-271322r1108582_rule | The Master Key must be backed up and stored in a secure location that is not on the SQL Server. |
| ☐ | SV-271323r1108585_rule | The Service Master Key must be backed up and stored in a secure location that is not on the SQL Server. |
| ☐ | SV-271324r1192911_rule | SQL Server must protect the confidentiality and integrity of all information at rest. |
| ☐ | SV-271327r1137657_rule | SQL Server must prevent unauthorized and unintended information transfer via Instant File Initialization (IFI). |
| ☐ | SV-271328r1137657_rule | SQL Server must prevent unauthorized and unintended information transfer via shared system resources. |
| ☐ | SV-271329r1137658_rule | Access to database files must be limited to relevant processes and to authorized, administrative users. |
| ☐ | SV-271331r1108609_rule | SQL Server and associated applications must reserve the use of dynamic code execution for situations that require it. |
| ☐ | SV-271332r1108612_rule | SQL Server and associated applications, when making use of dynamic code execution, must scan input data for invalid values that may indicate a code injection attack. |
| ☐ | SV-271334r1109125_rule | SQL Server must reveal detailed error messages only to documented and approved individuals or roles. |
| ☐ | SV-271341r1111081_rule | SQL Server must prevent nonprivileged users from executing privileged functions, to include disabling, circumventing, or altering implemented security safeguards/countermeasures. |
| ☐ | SV-271342r1108642_rule | Use of credentials and proxies must be restricted to necessary cases only. |
| ☐ | SV-271343r1108645_rule | SQL Server must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements. |
| ☐ | SV-271344r1111082_rule | SQL Server must provide a warning to appropriate support staff when allocated audit record storage volume reaches 75 percent of maximum audit record storage capacity. |
| ☐ | SV-271345r1109254_rule | SQL Server must provide an immediate real-time alert to appropriate support staff of all audit log failures. |
| ☐ | SV-271346r1109256_rule | SQL Server must record time stamps in audit records and application data that can be mapped to Coordinated Universal Time (UTC), formerly Greenwich Mean Time (GMT). |
| ☐ | SV-271349r1108938_rule | Windows must enforce access restrictions associated with changes to the configuration of the SQL Server instance. |
| ☐ | SV-271350r1111084_rule | SQL Server must enforce access restrictions associated with changes to the configuration of the instance. |
| ☐ | SV-271351r1167494_rule | SQL Server must produce audit records when attempts to modify SQL Server configuration and privileges occur within the database(s). |
| ☐ | SV-271358r1137659_rule | SQL Server services must be configured to run under unique dedicated user accounts. |
| ☐ | SV-271359r1137659_rule | SQL Server must maintain a separate execution domain for each executing process. |
| ☐ | SV-271362r1108702_rule | When invalid inputs are received, the SQL Server must behave in a predictable and documented manner that reflects organizational and system objectives. |
| ☐ | SV-271364r1137667_rule | Security-relevant software updates to SQL Server must be installed within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs). |
| ☐ | SV-271365r1138543_rule | Microsoft SQL Server products must be a version supported by the vendor. |
| ☐ | SV-271370r1111091_rule | SQL Server must generate audit records when successful and unsuccessful attempts to modify or delete security objects occur. |
| ☐ | SV-271375r1111093_rule | SQL Server must generate audit records when successful and unsuccessful logons or connection attempts occur. |
| ☐ | SV-271381r1111095_rule | SQL Server must generate audit records for all direct access to the database(s). |
| ☐ | SV-271385r1108771_rule | The system SQL Server must off-load audit data to a separate log management facility; this must be continuous and in near real time for systems with a network connection to the storage facility and weekly or more often for stand-alone systems. |
| ☐ | SV-271387r1111140_rule | The SQL Server Browser service must be disabled unless specifically required and approved. |
| ☐ | SV-271388r1111098_rule | SQL Server must configure SQL Server Usage and Error Reporting Auditing. |
| ☐ | SV-271389r1109133_rule | SQL Server must configure Customer Feedback and Error Reporting. |
| ☐ | SV-271400r1167497_rule | SQL Server must, for password-based authentication, require immediate selection of a new password upon account recovery. |
| ☐ | SV-274444r1137654_rule | The SQL Server default account [sa] must be disabled. |
| ☐ | SV-274445r1111103_rule | The SQL Server default account [sa] must have its name changed. |
| ☐ | SV-274446r1111106_rule | Execution of startup stored procedures must be restricted to necessary cases only. |
| ☐ | SV-274447r1111109_rule | The SQL Server Mirroring endpoint must use AES encryption. |
| ☐ | SV-274448r1111112_rule | The SQL Server Service Broker endpoint must use AES encryption. |
| ☐ | SV-274449r1111115_rule | SQL Server execute permissions to access the registry must be revoked unless specifically required and approved. |
| ☐ | SV-274450r1111117_rule | Filestream must be disabled unless specifically required and approved. |
| ☐ | SV-274451r1111120_rule | The Ole Automation Procedures feature must be disabled unless specifically required and approved. |
| ☐ | SV-274452r1111123_rule | The SQL Server User Options feature must be disabled unless specifically required and approved. |