8.2 Restrict access to starting and stopping the DB2 administration server

Information

The DB2 administration server responds to remote requests from administration tools and client utilities. It is recommended that only administrators are allowed to start and stop the DB2 administration server.

Allowing only privileged users to start and stop the DB2 administration server will help ensure that the DB2 administration server is controlled by authorized administrators.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

1. Connect to the host
2. Review users and groups that have access to start and stop the DB2 instance
3. Revoke access from any unnecessary users.

See Also

https://workbench.cisecurity.org/files/1654