Skip to content

Redis Enterprise 6.x Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Redis Enterprise DBMS must generate audit records for DoD-defined auditable events within all DBMS/database components.

    <VulnDiscussion>Redis Enterprise does not generate all the DoD-required audit records. This could lead to incomplete information as follows:...
    Rule Medium Severity
  • SRG-APP-000164-DB-000401

    <GroupDescription></GroupDescription>
    Group
  • If DBMS authentication using passwords is employed, Redis Enterprise DBMS must enforce the DOD standards for password complexity and lifetime.

    &lt;VulnDiscussion&gt;OS/enterprise authentication and identification must be used (SRG-APP-000023-DB-000001). Native DBMS authentication may be us...
    Rule Medium Severity
  • SRG-APP-000456-DB-000400

    <GroupDescription></GroupDescription>
    Group
  • Redis Enterprise products must be a version supported by the vendor.

    &lt;VulnDiscussion&gt;Unsupported commercial and database systems should not be used because fixes to newly identified bugs will not be implemented...
    Rule High Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules