6.1.11 Secure CREATETAB Authority

Information

The CREATETAB (create table) role grants the authority to a user to create tables within a specific database. It is recommended that the CREATETAB role be granted to authorized users only.

Review all users that have access to this authority to avoid the addition of unnecessary and/or inappropriate users.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Revoke this permission from any unauthorized users.

- Connect to the Db2 database. db2 => connect to <dbname>
- Run the following command: db2 => REVOKE CREATETAB ON DATABASE FROM USER <username>

See Also

https://workbench.cisecurity.org/benchmarks/23492

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: IBM_DB2DB

Control ID: a6711f7d888a2ec723c0b849201fdbee3f6cf4350fc3f2cdf776a107427fca45