Skip to content

Database Security Requirements Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The DBMS must for password-based authentication, store passwords using an approved salted key derivation function, preferably using a keyed hash.

    The DOD standard for authentication is DOD-approved PKI certificates. Authentication based on user ID and password may be used only when it is not possible to employ a PKI certificate, and require...
    Rule High Severity
  • SRG-APP-000172

    Group
  • If passwords are used for authentication, the DBMS must transmit only encrypted representations of passwords.

    The DoD standard for authentication is DoD-approved PKI certificates. Authentication based on User ID and Password may be used only when it is not possible to employ a PKI certificate, and require...
    Rule High Severity
  • SRG-APP-000175

    Group
  • SRG-APP-000176

    Group
  • SRG-APP-000177

    Group
  • SRG-APP-000178

    Group
  • SRG-APP-000179

    Group
  • SRG-APP-000180

    Group
  • SRG-APP-000211

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules