Page 2
Table of Contents
Terms of Use ..................................................................................................................... 1
Table of Contents ............................................................................................................. 2
Overview ............................................................................................................................ 5
Intended Audience ..................................................................................................................... 5
Consensus Guidance ................................................................................................................. 6
Typographical Conventions ...................................................................................................... 7
Recommendation Definitions ......................................................................................... 8
Title ............................................................................................................................................... 8
Assessment Status .................................................................................................................... 8
Automated ............................................................................................................................................... 8
Manual...................................................................................................................................................... 8
Profile ........................................................................................................................................... 8
Description .................................................................................................................................. 8
Rationale Statement ................................................................................................................... 8
Impact Statement........................................................................................................................ 9
Audit Procedure .......................................................................................................................... 9
Remediation Procedure ............................................................................................................. 9
Default Value ............................................................................................................................... 9
References .................................................................................................................................. 9
CIS Critical Security Controls
®
(CIS Controls
®
) ...................................................................... 9
Additional Information ............................................................................................................... 9
Profile Definitions ..................................................................................................................... 10
Acknowledgements .................................................................................................................. 12
Recommendations ......................................................................................................... 13
1 Operating System Level Configuration .............................................................................. 13
1.1 Place Databases on Non-System Partitions (Manual) .......................................................................... 14
1.2 Use Dedicated Least Privileged Account for MySQL Daemon/Service (Automated) ............................ 17
1.3 Disable MySQL Command History (Automated) ................................................................................... 19
1.4 Verify That the MYSQL_PWD Environment Variable Is Not In Use (Automated) ................................. 21
1.5 Ensure Interactive Login is Disabled (Automated) ................................................................................ 23
1.6 Verify That 'MYSQL_PWD' is Not Set in Users' Profiles (Automated) .................................................. 25
2 Installation and Planning ...................................................................................................... 26
2.1 Backup and Disaster Recovery ..................................................................................................... 27
2.1.1 Backup Policy in Place (Manual) ........................................................................................................ 28
2.1.2 Verify Backups are Good (Manual) .................................................................................................... 29
2.1.3 Secure Backup Credentials (Manual) ................................................................................................. 30
相关文档
评论