Revision 1.1Feb 25, 2026

Functional Update
  • DISA_STIG_MSSQL_2014_Instance-OS_v2r4.audit from DISA MS SQL Server 2014 Instance v2r4 STIG
  • SQL4-00-014000 - SQL Server and/or the operating system must protect its audit configuration from unauthorized modification.
  • SQL4-00-014100 - SQL Server and the operating system must protect SQL Server audit features from unauthorized removal.
  • SQL4-00-015400 - SQL Server software installation account(s) must be restricted to authorized users.
  • SQL4-00-034200 - SQL Server must disable communication protocols not required for operation.
  • SQL4-00-034800 - SQL Server must implement and/or support cryptographic mechanisms preventing the unauthorized disclosure of organization-defined information at rest on organization-defined information system components.
  • SQL4-00-035400 - Security-relevant software updates to SQL Server must be installed within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).
Miscellaneous
  • Metadata updated.
  • Platform check updated.
  • References updated.
  • Variables updated.