CIS MySQL 5.7 Enterprise Linux OS L1 v1.0.0

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS MySQL 5.7 Enterprise Linux OS L1 v1.0.0

Updated: 12/7/2022

Authority: Operating Systems and Applications

Plugin: Unix

Revision: 1.16

Estimated Item Count: 29

File Details

Filename: CIS_MySQL_5.7_Enterprise_Benchmark_v1.0.0_Level_1_OS_Linux.audit

Size: 47.4 kB

MD5: c3fac7db945371ad536257a555bbb43d
SHA256: 711f7061e5951104f59d110812857b1c75daca3ce2dd7dd56f8ee17c1f4531cc

Audit Items

DescriptionCategories
1.1 Place Databases on Non-System Partitions
1.2 Use Dedicated Least Privileged Account for MySQL Daemon/Service
1.4 Verify that 'MYSQL_PWD' Is Not Set
2.1 Dedicate Machine Running MySQL
2.2 Do Not Specify Passwords in Command Line - History
2.2 Do Not Specify Passwords in Command Line - Process Listing
2.3 Do Not Reuse User Accounts
3.1 Ensure 'datadir' Has Appropriate Permissions and Ownership
3.2 Ensure 'log_bin_basename' Files Have Appropriate Permissions and Ownership
3.3 Ensure 'log_error' Has Appropriate Permissions and Ownership
3.4 Ensure 'slow_query_log' Has Appropriate Permissions and Ownership
3.5 Ensure 'relay_log_basename' Files Have Appropriate Permissions and Ownership
3.6 Ensure 'general_log_file' Has Appropriate Permissions and Ownership
3.7 Ensure SSL Key Files Have Appropriate Permissions and Ownership
3.8 Ensure Plugin Directory Has Appropriate Permissions and Ownership
3.9 Ensure 'audit_log_file' has Appropriate Permissions and Ownership
4.5 Ensure 'mysqld' Is Not Started with '--skip-grant-tables'
4.5 Ensure 'mysqld' Is Not Started with '--skip-grant-tables' - /etc/my.cnf
4.5 Ensure 'mysqld' Is Not Started with '--skip-grant-tables' - /etc/mysql/my.cnf
4.5 Ensure 'mysqld' Is Not Started with '--skip-grant-tables' - SYSCONFDIR/my.cnf
6.4 Ensure 'log-raw' Is Set to 'OFF' - /etc/my.cnf
6.4 Ensure 'log-raw' Is Set to 'OFF' - /etc/mysql/my.cnf
6.4 Ensure 'log-raw' Is Set to 'OFF' - SYSCONFDIR/my.cnf
6.4 Ensure 'log-raw' Is Set to 'OFF' - SYSCONFDIRmy.cnf
7.3 Ensure Passwords Are Not Stored in the Global Configuration
7.3 Ensure Passwords Are Not Stored in the Global Configuration - /etc/my.cnf
7.3 Ensure Passwords Are Not Stored in the Global Configuration - /etc/mysql/my.cnf
7.3 Ensure Passwords Are Not Stored in the Global Configuration - SYSCONFDIR/my.cnf
MySQL 5.7 Enterprise Edition is installed