Skip to content

Database Security Requirements Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000091

    Group
  • The DBMS must be able to generate audit records when privileges/permissions are retrieved.

    Under some circumstances, it may be useful to monitor who/what is reading privilege/permission/role information. Therefore, it must be possible to configure auditing to do this. DBMSs typically mak...
    Rule Medium Severity
  • SRG-APP-000091

    Group
  • SRG-APP-000092

    Group
  • The DBMS must initiate session auditing upon startup.

    Session auditing is for use when a user's activities are under investigation. To be sure of capturing all activity during those periods when session auditing is in use, it needs to be in operation ...
    Rule Medium Severity
  • SRG-APP-000095

    Group
  • SRG-APP-000096

    Group
  • The DBMS must produce audit records containing time stamps to establish when the events occurred.

    Information system auditing capability is critical for accurate forensic analysis. Without establishing when events occurred, it is impossible to establish, correlate, and investigate the events re...
    Rule Medium Severity
  • SRG-APP-000097

    Group
  • SRG-APP-000098

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules