3.1.7 Disable Instance Discoverability (DISCOVER_INST)

Information

The DISCOVER_INST parameter specifies whether the instance can be discovered in the network. It is recommended that instances not be discoverable.

Rationale:

Discovery capabilities may be used by a malicious entity to derive the names of and target Db2 instances.

Solution

Attach to the Db2 instance:

db2 => attach to <db2instance>

Run the following command:

db2 => update database manager configuration using discover_inst disable

See Also

https://workbench.cisecurity.org/benchmarks/10752

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Unix

Control ID: 7bc5d61093ddc8965b12497c15cca7bf0738624877439b93d47219fb13b891c6