10.2 Restrict access to the DB2 Configuration Assistant utility

Information

The DB2 Configuration Assistant is a management tool that manages all connectivity setup to the DB2 instances and databases. It is recommended that access to the Configuration Assistant utility be granted to authorized users only.

Secure this application where applicable, since it has access to the DB2 instance name, the host it resides on, and the database name, and the port number.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

To revoke access to the DB2 Configuration Assistant from unnecessary users and groups:
1. Connect to the host
2. Review users and groups that have access to start the DB2 Configuration Assistant.
3. Revoke access from unnecessary users and groups.

See Also

https://workbench.cisecurity.org/files/1654