Skip to content

MongoDB Enterprise Advanced 4.x Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000121-DB-000202

    Group
  • MongoDB must protect its audit features from unauthorized access.

    Protecting audit data also includes identifying and protecting the tools used to view and manipulate log data. Depending upon the log format and application, system and application log tools may p...
    Rule Medium Severity
  • SRG-APP-000141-DB-000092

    Group
  • Unused database components that are integrated in MongoDB and cannot be uninstalled must be disabled.

    Information systems are capable of providing a wide variety of functions and services. Some of the functions and services, provided by default, may not be necessary to support essential organizatio...
    Rule Medium Severity
  • SRG-APP-000142-DB-000094

    Group
  • Unused database components that are integrated in MongoDB and cannot be uninstalled must be disabled.

    Information systems are capable of providing a wide variety of functions and services. Some of the functions and services, provided by default, may not be necessary to support essential organizatio...
    Rule Medium Severity
  • SRG-APP-000172-DB-000075

    Group
  • If passwords are used for authentication, MongoDB must transmit only encrypted representations of passwords.

    The DoD standard for authentication is DoD-approved PKI certificates. Authentication based on User ID and Password may be used only when it is not possible to employ a PKI certificate, and require...
    Rule High Severity
  • SRG-APP-000211-DB-000122

    Group
  • SRG-APP-000225-DB-000153

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules