4.1.15 Disable Database Discoverability (DISCOVER_DB)

Information

The DISCOVER_DB parameter specifies whether the database can be discovered in the network. It is recommended that databases not be discoverable.

Rationale:

Discovery capabilities may be used by a malicious entity to derive the names of and target Db2 databases.

Solution

Connect to the Db2 database.

db2 => connect to <dbname>

Run the following command:

db2 => update database configuration using discover_db disable

See Also

https://workbench.cisecurity.org/benchmarks/10752

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Windows

Control ID: 344467c2b89a2b0c0d145bfb728eb9e61e1482074d24da6272ca6c4fc81cc8db