Enable server-based authentication Details The srvcon_auth parameter specifies how and where authentication is to take place for incoming connections to the server. It...
Enable SSL communication with LDAP server Details The communication layer between a DB2 instance and the LDAP server should be encrypted. It is recommended that the...
Encrypt user data across the network Details DB2 supports a number of authentication mechanisms. It is recommended that the DATA_ENCRYPT authentication mechanism be used. Solution Suggested...
Ensure permissions on communication exit library locations Details If the permissions on the DB2 communication exit library directories are not set properly, the contents of those directories...
Establish retention set size for backups Details The num_db_backups parameter specifies the number of backups to retain for a database before marking the oldest backup as...
Protecting Backups Details Backups of your database should be stored securely in a location with full access for administrators, read and execute...
Remove Default Databases Details A DB2 instance may come installed with default databases. It is recommended that the SAMPLE database be removed. Solution...
Require explicit authorization for cataloging Details DB2 can be configured to allow users that do not possess the SYSADM authority to catalog and uncatalog databases...
Require instance name for discovery requests Details The discover parameter determines what kind of discovery requests, if any, the DB2 server will fulfill. It is recommended...
Review Users, Groups, and Roles – Groups list Details With row and column access control, individuals are permitted access to only the subset of data that is required...