Skip to main content
CUI

Documentation - V-213995

V-213995

MS SQL Server 2016 Instance Security Technical Implementation Guide

CAT II

Title

SQL Server must be able to generate audit records when successful and unsuccessful attempts to access security objects occur.

Description

<VulnDiscussion>Changes to the security configuration must be tracked. This requirement applies to situations where security data is retrieved or modified via data manipulation operations, as opposed to via specialized security functionality. In an SQL environment, types of access include, but are not necessarily limited to: SELECT INSERT UPDATE DELETE EXECUTE To aid in diagnosis, it is necessary to keep track of failed attempts in addition to the successful ones. Satisfies: SRG-APP-0...

Fix Text (Documentation Requirement)

Deploy an audit to audit the retrieval of privilege/permission/role membership information when successful and unsuccessful attempts to access security objects occur. See the supplemental file "SQL 2016 Audit.sql".

Documentation Status

Cancel
CUI