6.1.15 Secure EXTERNALROUTINE Authority

Information

The EXTERNALROUTINE authority grants a user the privilege to create user-defined functions and procedures in a specific database.

Rationale:

All users with this authority should be regularly reviewed and approved.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Revoke this permission from any unauthorized users.

Connect to the Db2 database.

db2 => connect to <dbname>

Run the following command:

db2 => REVOKE CREATE_EXTERNAL_ROUTINE ON DATABASE

FROM USER <username>

See Also

https://workbench.cisecurity.org/benchmarks/23492

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: IBM_DB2DB

Control ID: e991e3253abda2bacb7c7cb43de0961ce7da2e4d0845a5756db72e62588a287c