DISA MS SQL Server 2016 Instance STIG v3r6 Windows

Audit Details

Name: DISA MS SQL Server 2016 Instance STIG v3r6 Windows

Updated: 6/2/2026

Authority: DISA STIG

Plugin: Windows

Revision: 1.1

Estimated Item Count: 16

File Details

Filename: DISA_STIG_MSSQL_2016_Instance-OS_v3r6.audit

Size: 57.6 kB

MD5: f0dedc6c93be8d5f6ed4d2c7451f25e8
SHA256: ea052a96153a55d98b06f1219461ed690269c630bb2efd11c4505b6c2dd0caac

Audit Changelog

 
Revision 1.1

Jun 2, 2026

Miscellaneous
  • Metadata updated.
  • See also link updated.
  • Variables updated.
Removed
  • SQL6-D0-007700 - SQL Server must be configured to prohibit or restrict the use of organization-defined ports, as defined in the PPSM CAL and vulnerability assessments.
  • SQL6-D0-009200 - SQL Server must maintain the authenticity of communications sessions by guarding against man-in-the-middle attacks that guess at Session ID values.
  • SQL6-D0-015600 - SQL Server must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to provision digital signatures.
  • SQL6-D0-015700 - SQL Server must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to generate and validate cryptographic hashes.
  • SQL6-D0-015800 - SQL Server must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to protect unclassified information requiring confidentiality and cryptographic protection, in accordance with the data owners requirements.