CIS MySQL 5.6 Enterprise Linux OS L1 v1.0.0

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS MySQL 5.6 Enterprise Linux OS L1 v1.0.0

Updated: 10/19/2016

Authority: CIS

Plugin: Unix

Revision: 1.7

Estimated Item Count: 27

Audit Items

DescriptionCategories
1.2 Use Dedicated Least Privileged Account for MySQL Daemon/Service

ACCESS CONTROL

1.4 Verify That the MYSQL_PWD Environment Variables Is Not In Use

IDENTIFICATION AND AUTHENTICATION

1.6 Verify That 'MYSQL_PWD' Is Not Set In Users' Profiles - .bash_profile

IDENTIFICATION AND AUTHENTICATION

1.6 Verify That 'MYSQL_PWD' Is Not Set In Users' Profiles - .bashrc

IDENTIFICATION AND AUTHENTICATION

1.6 Verify That 'MYSQL_PWD' Is Not Set In Users' Profiles - .profile

IDENTIFICATION AND AUTHENTICATION

2.3 Do Not Specify Passwords in Command Line
3.1 Ensure 'datadir' Has Appropriate Permissions

CONFIGURATION MANAGEMENT

3.2 Ensure 'log_bin_basename' Files Have Appropriate Permissions

CONFIGURATION MANAGEMENT

3.3 Ensure 'log_error' Has Appropriate Permissions

CONFIGURATION MANAGEMENT

3.4 Ensure 'slow_query_log' Has Appropriate Permissions

CONFIGURATION MANAGEMENT

3.5 Ensure 'relay_log_basename' Files Have Appropriate Permissions

CONFIGURATION MANAGEMENT

3.6 Ensure 'general_log_file' Has Appropriate Permissions

CONFIGURATION MANAGEMENT

3.7 Ensure SSL Key Files Have Appropriate Permissions

CONFIGURATION MANAGEMENT

3.8 Ensure Plugin Directory Has Appropriate Permissions

CONFIGURATION MANAGEMENT

3.9 Ensure 'audit_log_file' has Appropriate Permissions

CONFIGURATION MANAGEMENT

4.5 Ensure 'mysqld' Is Not Started with '--skip-grant-tables'
4.5 Ensure 'mysqld' Is Not Started with '--skip-grant-tables' - @SYSCONFDIR@/my.cnf

ACCESS CONTROL

4.5 Ensure 'mysqld' Is Not Started with '--skip-grant-tables' - /etc/my.cnf

ACCESS CONTROL

4.5 Ensure 'mysqld' Is Not Started with '--skip-grant-tables' - /etc/mysql/my.cnf

ACCESS CONTROL

6.4 Ensure 'log-raw' Is Set to 'OFF' - @SYSCONFDIR@/my.cnf

CONFIGURATION MANAGEMENT

6.4 Ensure 'log-raw' Is Set to 'OFF' - @[email protected]
6.4 Ensure 'log-raw' Is Set to 'OFF' - /etc/my.cnf

CONFIGURATION MANAGEMENT

6.4 Ensure 'log-raw' Is Set to 'OFF' - /etc/mysql/my.cnf

CONFIGURATION MANAGEMENT

7.3 Ensure Passwords Are Not Stored in the Global Configuration
7.3 Ensure Passwords Are Not Stored in the Global Configuration - @SYSCONFDIR@/my.cnf

IDENTIFICATION AND AUTHENTICATION

7.3 Ensure Passwords Are Not Stored in the Global Configuration - /etc/my.cnf

IDENTIFICATION AND AUTHENTICATION

7.3 Ensure Passwords Are Not Stored in the Global Configuration - /etc/mysql/my.cnf

IDENTIFICATION AND AUTHENTICATION