6.1.16 Secure QUIESCECONNECT Authority

Information

The QUIESCECONNECT role grants the authority to a user to access a database even in the quiesced state.

Rationale:

It is recommended that the QUIESCECONNECT role be granted to authorized users only.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Connect to the Db2 database.

db2 => connect to <dbname>

Run the following command:

db2 => REVOKE QUIESCE_CONNECT ON DATABASE FROM USER <username>

See Also

https://workbench.cisecurity.org/benchmarks/23492

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: IBM_DB2DB

Control ID: c4ed08ab356f8224786df74067b152376aa8b17e1e476afda5f5c64c501dcae7