7.2 Secure SYSCTRL authority - SYSCTRL Group

Information

The sysctrl_group parameter defines the system administrator group with system control (SYSCTRL) authority. It is recommended that the sysctrl_group group contains authorized users only.

NOTE - No group members found or the SYSCTRL_GROUP parameter is not defined.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Define a valid group name for the SYSCTRL group.
1. Attach to the DB2 instance.
db2 => attach to $DB2INSTANCE
2. Run the following command from the DB2 command window-
db2 => update database manager configuration using sysctrl_group <sys control group name>

See Also

https://workbench.cisecurity.org/files/162

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(5), CSCv6|5.1

Plugin: Windows

Control ID: 89c1c18ad74e7befce5e6e57a34c2d7da95de5c18dede47269ccd42ce6183eaa