Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Note

Click on the Policy Template name to order the table according to Security Checks marked as default.

Access Security Checks
CIS for SQL Server 2000
CIS for SQL Server 2005
CIS for SQL Server 2008
CIS for SQL Server 2008
R2
CIS for SQL Server 2012
CIS for SQL Server 2014
CIS for SQL Server 2016
CIS for SQL Server 2017
CIS for SQL Server 2019
CIS for SQL Server 2022
DISA-NIST STIG for SQL Server 2012
DISA-NIST STIG for SQL Server 2014
DISA-NIST STIG for SQL Server 2016
European Union General Data Protection Regulation (GDPR)
HIPAA Guidelines for SQL Server
IDERA Level 1 - Basic Protection
IDERA Level 2 - Balanced Protection
IDERA Level 3 - Strong Protection
MS Best Practices Analyzer
NERC Critical Infrastructure Protection
PCI-DSS Guidelines for SQL Server
SNAC for SQL 2000
SOX Section 404
SRR Checklist for SQL Server 2000
SRR Checklist for SQL Server 2005 or later
Always Encrypted
Appropriate cryptographic modules have been used to encrypt data.
Assembly host policy
Backup Encryption (Native)
Backup Encryption (Non-Native)
Certificate private keys were never exported
Contained database authentication type
DAC Remote Access
Dangerous Extended Stored Procedures (XSPs)
Database Master Key encrypted by Service Master Key
Database Master Keys Encrypted by Password
Database roles and members
Dynamic Data Masking
Encryption Methods
Files On Drives Not Using NTFS
Fixed Roles Assigned To public Or guest
Guest User Enabled
Linked server is running as a member of sysadmin group
NTFS Folder Level Encryption
Operating System Version
Public role permissions
Remote Access
Required Administrative Accounts Do Not Exist
Row-Level Security
Server roles and members
Signed Objects
SQL Job permissions
SQL Jobs and Agent
SQL Server Browser Running
SQL Server database level encryption
Startup Stored Procedures
Startup Stored Procedures Enabled
Startup Stored Procedures permissions
Stored Procedures Encrypted
Symmetric key
Symmetric Keys Not Encrypted with a Certificate
Sysadmins Own Trustworthy Databases
Transparent Data Encryption
Unacceptable Database Ownership
User Defined Extended Stored Procedures (XSPs)
Analysis Services Running
XXX










X
XX

X



Asymmetric Key Size



XXXXXXX














Auto_Close set for contained databases




XXXXXX





XX






Backups compliance with RTO and RPO requirements










X







X




BUILTIN/Administrators Is sysadmin
XXX










XXXXX
X

XX
CLR Enabled


XXXXXXXX


X


X






Common criteria compliance


X











XXX






Data Files On System Drive














XXXX






Database-level Firewall Rules















XXX






Databases Are Trustworthy



XXXXXXXXXXXX

X

X


X
Default Trace Enabled


XXXXXXXX














Full-Text Search Running

XX










X
XX






HADR is configured













X


X






Hide Instance Option is set



XXXXXXX




XXX






Integration Services
X























Linked servers are configured

























Max Number of concurrent sessions










X



XXX






Maximum number of error log files


XXXXXXXX





XX






Ole automation procedures


XXXXXXXX


X

XX






Other General Domain Accounts

















X






Replication Enabled

XX










X
XX

X

XX
sa Account Not Disabled



XXXXXXXXXX
XXXX
XX



sa Account Not Disabled Or Renamed

XXXXXXXXXXXX
XXXX
XX


X
Sample Databases Exist
XXX






XXXX

XX


X
XX
Server Is Domain Controller

XX










XXXXX





Server-level Firewall Rules















XXX






Shutdown SQL Server on Trace Failure











XX



X






SQL Agent Mail
XXX










X
XX


X

X
SQL Mail Or Database Mail Enabled
XXXXXXXXXX



X
XX


X
XX
SQL Server Installation Directories On System Drive














XXXX






SQL Server Version
XXXXXXXXXX



XXXXXXXX
XX
System Table Updates
XXX










XXXX

X

X
Transport Layer Security













X


X






Unauthorized Account Check














X

X
XX


X
User created 'sa' account does not exist





XXXXX





XX






VSS Writer Running














X

X

X



xp_cmdshell Enabled

XXXXXX


XXXXXXXX

X


X
xp_cmdshell Proxy Account Exists

XX










XXXXX
X



Scroll pdf ignore
Excerpt
Newtabfooter
aliasIDERA
urlhttp://www.idera.com
|
Newtabfooter
aliasProducts
urlhttps://www.idera.com/productssolutions/sqlserver
|
Newtabfooter
aliasPurchase
urlhttps://www.idera.com/buynow/onlinestore
|
Newtabfooter
aliasSupport
urlhttps://idera.secure.force.com/
|
Newtabfooter
aliasCommunity
urlhttp://community.idera.com
|
Newtabfooter
aliasResources
urlhttp://www.idera.com/resourcecentral
|
Newtabfooter
aliasAbout Us
urlhttp://www.idera.com/about/aboutus
|
Newtabfooter
aliasLegal
urlhttps://www.idera.com/legal/termsofuse