1.3 Leverage the least privilege principle

Information

The DB2 database instance will execute under the context of a given security principle. It is recommended that this service have the least privileges possible. Furthermore, it is advisable to have the DB2 service executed using the DB2 instance owner and monitor such accounts for unauthorized access to the sensitive data.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Ensure that all accounts have the absolute minimal privilege granted to perform their tasks.

See Also

https://workbench.cisecurity.org/files/162