V-213952
MS SQL Server 2016 Instance Security Technical Implementation Guide
Title
SQL Server software installation account must be restricted to authorized users.
Description
<VulnDiscussion>When dealing with change control issues, it should be noted any changes to the hardware, software, and/or firmware components of the information system and/or application can have significant effects on the overall security of the system. If the system were to allow any user to make changes to software libraries, then those changes might be implemented without undergoing the appropriate testing and approvals that are part of a robust change management process. Accordingly, only...
Fix Text (Documentation Requirement)
From a command prompt, open lusrmgr.msc. Navigate to Users and right-click Individual User. Select Properties >> Member Of. Configure SQL Server and OS settings and access controls to restrict user access to objects and data that the user is authorized to view/use.