CIS MySQL 8.0 Enterprise Linux OS L1 v1.2.0

Audit Details

Name: CIS MySQL 8.0 Enterprise Linux OS L1 v1.2.0

Updated: 8/9/2022

Authority: CIS

Plugin: Unix

Revision: 1.0

Estimated Item Count: 34

File Details

Filename: CIS_MySQL_8.0_Enterprise_Benchmark_v1.2.0_Level_1_OS_Linux.audit

Size: 75 kB

MD5: 5980c9ae8c8516fa4f732e61c7a32c02
SHA256: 98b85d56248b33c08ef50a4416e3006c73a168cf8666f07d8cb1763028b8b466

Audit Items

DescriptionCategories
1.1 Place Databases on Non-System Partitions

SYSTEM AND COMMUNICATIONS PROTECTION

1.2 Use Dedicated Least Privileged Account for MySQL Daemon/Service

ACCESS CONTROL

1.4 Verify That the MYSQL_PWD Environment Variable is Not in Use

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.6 Verify That 'MYSQL_PWD' is Not Set in Users' Profiles - .bash_profile

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.6 Verify That 'MYSQL_PWD' is Not Set in Users' Profiles - .bashrc

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.6 Verify That 'MYSQL_PWD' is Not Set in Users' Profiles - .profile

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.1.1 Backup Policy in Place

CONTINGENCY PLANNING

2.1.2 Verify Backups are Good

CONTINGENCY PLANNING

2.1.3 Secure Backup Credentials

ACCESS CONTROL, CONTINGENCY PLANNING, MEDIA PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION

2.1.4 The Backups Should be Properly Secured

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

2.1.6 Disaster Recovery (DR) Plan

CONTINGENCY PLANNING

2.1.7 Backup of Configuration and Related Files

CONTINGENCY PLANNING

2.3 Dedicate the Machine Running MySQL

SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Do Not Specify Passwords in the Command Line

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.6 Ensure Non-Default, Unique Cryptographic Material is in Use

CONFIGURATION MANAGEMENT

3.1 Ensure 'datadir' Has Appropriate Permissions - datadir Has Appropriate Permissions and Ownership

ACCESS CONTROL, MEDIA PROTECTION

3.2 Ensure 'log_bin_basename' Files Have Appropriate Permissions - log_bin_basename Files Have Appropriate Permissions and Ownership

ACCESS CONTROL, MEDIA PROTECTION

3.3 Ensure 'log_error' Has Appropriate Permissions - log_error Has Appropriate Permissions and Ownership

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.4 Ensure 'slow_query_log' Has Appropriate Permissions - slow_query_log Has Appropriate Permissions and Ownership

ACCESS CONTROL, MEDIA PROTECTION

3.5 Ensure 'relay_log_basename' Files Have Appropriate Permissions - relay_log_basename Files Have Appropriate Permissions and Ownership

ACCESS CONTROL, MEDIA PROTECTION

3.6 Ensure 'general_log_file' Has Appropriate Permissions - general_log_file Has Appropriate Permissions and Ownership

ACCESS CONTROL, MEDIA PROTECTION

3.7 Ensure SSL Key Files Have Appropriate Permissions

ACCESS CONTROL, MEDIA PROTECTION

3.8 Ensure Plugin Directory Has Appropriate Permissions

ACCESS CONTROL, MEDIA PROTECTION

3.9 Ensure 'audit_log_file' Has Appropriate Permissions - audit_log_file has Appropriate Permissions and Ownership

ACCESS CONTROL, MEDIA PROTECTION

3.10 Secure MySQL Keyring - keyring_aws_conf_file

ACCESS CONTROL, MEDIA PROTECTION

3.10 Secure MySQL Keyring - keyring_encrypted_file_data_path

ACCESS CONTROL, MEDIA PROTECTION

3.10 Secure MySQL Keyring - keyring_file_data_path

ACCESS CONTROL, MEDIA PROTECTION

3.10 Secure MySQL Keyring - keyring_hashicorp_store_path

ACCESS CONTROL, MEDIA PROTECTION

3.10 Secure MySQL Keyring - keyring_oci_key_file

ACCESS CONTROL, MEDIA PROTECTION

3.10 Secure MySQL Keyring - keyring_okv_path

ACCESS CONTROL, MEDIA PROTECTION

4.5 Ensure 'mysqld' is Not Started With '--skip-grant-tables'

ACCESS CONTROL, MEDIA PROTECTION

6.4 Ensure 'log-raw' is Set to 'OFF'

MEDIA PROTECTION

7.2 Ensure Passwords are Not Stored in the Global Configuration

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

CIS_MySQL_8.0_Enterprise_Benchmark_v1.2.0_Level_1_OS_Linux.audit from CIS Oracle MySQL 8.0 Enterprise Edition Benchmark