Enable Database Maintenance – ‘auto_maint = on’ Details It is recommended that DB2 Automatic Maintenance tool be used to ensure that the instance is performing optimally. Supportive...
Enable instance health monitoring – ‘health_mon = on’ Details the corresponding database objects. Supportive Information The following resource is also helpful. https://workbench.cisecurity.org/files/155 This security hardening control applies to...
Enable server-based authentication – ‘srvcon_auth = server’ Details NOTE: If the authentication setting at the database configuration level is set to DATA_ENCRYPT (in benchmark 3.1.2), this setting...
Enable SSL communication with LDAP server Details It is recommended that the ENABLE_SSL parameter in the IBMLDAPSecurity.ini file be set to TRUE. Supportive Information The following...
Enforce Label-Based Access Controls Implementation Details Ensure that the database has label-based access controls (LBAC) component implemented to protect senstive data. It is recommended that...
Encrypt user data across the network – ‘authentication = Data_Encrypt’ Details DB2 supports a number of authentication mechanisms. Supportive Information The following resource is also helpful. https://workbench.cisecurity.org/files/155 This security hardening...
Establish an administrator group – ‘sysadm_group value’ Details The sysadm_group parameter defines the system administrator group with SYSADM authority for the DB2 instance. It is recommended that...
Establish retention set size for backups – ‘num_db_backups <= 100' Details NOTE : Update DB2_VERSION to the appropriate value for your local environment. Supportive Information The following resource is also...
Establish system control group – ‘sysctrl_group value’ Details It is recommended that sysctrl_group group contains authorized users only. Supportive Information The following resource is also helpful. https://workbench.cisecurity.org/files/155...
Install the latest Fixpak Details Periodically, IBM releases ‘Fixpak’ to enhance features and resolve defects, including security defects. It is recommended that the DB2...