4.1 Review Organization's Policies against DB2 RCAC Policies

Information

DB2 Row and Column Access Control (RCAC) Policies control access to DB2 tables. They should match the organization's security and database access policies, and they should be regularly reviewed for gaps.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

1. Create RCAC policies for each 'gap' listed from the Audit procedure.
2. Review the newly created DB2 RCAC policy against the organization's written policies.

See Also

https://workbench.cisecurity.org/files/162