II - Mission Support Public
Rules and Groups employed by this XCCDF Profile
-
When updates are applied to SQL Server software, any software components that have been replaced or made unnecessary must be removed.
Previous versions of DBMS components that are not removed from the information system after updates have been installed may be exploited by adversaries. Some DBMSs' installation tools may remov...Rule Medium Severity -
SRG-APP-000456-DB-000390
Group -
Security-relevant software updates to SQL Server must be installed within the time period directed by an authoritative source (e.g. IAVM, CTOs, DTMs, and STIGs).
Security flaws with software applications, including database management systems, are discovered daily. Vendors are constantly updating and patching their products to address newly discovered secur...Rule Medium Severity -
SRG-APP-000492-DB-000332
Group -
SQL Server must be able to generate audit records when successful and unsuccessful attempts to access security objects occur.
Changes to the security configuration must be tracked. This requirement applies to situations where security data is retrieved or modified via data manipulation operations, as opposed to via spec...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.