4.1.4 Disable Database Discovery (DISCOVER_DB)

Information

The DISCOVER_DB parameter specifies if the database will respond to a discovery request from a client. It is recommended that this parameter be set to DISABLE.

Rationale:

Setting the database discovery to disabled can hide a database with sensitive data.

Solution

Connect to the Db2 database

db2 => connect to <dbname>

Run the following command:

db2 => update database configuration using discover_db disable

See Also

https://workbench.cisecurity.org/benchmarks/10752

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Windows

Control ID: 679e436e6ec66120c6653c35a1d412d49b679b0db3e85e10802784d9c13bf2ab