BigFix Compliance: Updated CIS Checklist for MS SQL Server 2008 R2, published 2023-01-17

Product:
BigFix Compliance

Title:
Updated CIS Checklist for MS SQL Server 2008 R2 with bug fixes

Security Benchmark:
CIS_Microsoft_SQL_Server_2008_R2_Database_Engine_Benchmark V1.5.0

Published Sites:
CIS Checklist for MS SQL Server 2008 R2, site version 6
(The site version is provided for air-gap customers.)

Details:

  • Fixed and Improved implementation for the following check to avoid failure when any databases are offline or any special characters in database name
    • 3.2 - Ensure CONNECT permissions on the ‘guest user’ is Revoked within all SQL Server databases excluding the master, msdb and tempdb
    • 7.1 - Ensure ‘Symmetric Key encryption algorithm’ is set to ‘AES_128’ or higher in non-system databases
    • 7.2 - Ensure Asymmetric Key Size is set to ‘greater than or equal to 2048’ in non-system databases

Actions to take:

More information:
To know more about the BigFix Compliance SCM checklists, please see the following resources:

We hope you find this latest release of SCM content useful and effective. Thank you!

– The BigFix Compliance team