3.3.4 Prevent execution of expired tasks

Information

The exec_exp_task parameter controls whether the DB2 Scheduler will initialize past tasks that were scheduled but not yet executed. It is recommended that this parameter be set to NO.

This will help ensure sequestered jobs are not invoked by accident, which may have malicious scripts associated with the job. Ensure to review all expired jobs before restarting them.

Solution

1. Attach to the DB2 instance.
db2 => attach to $DB2INSTANCE
2. Run the following command from the DB2 command window:
db2 => update database manager configuration using exec_exp_task no
Default Value:
The default value for exec_exp_task is NO.

See Also

https://workbench.cisecurity.org/files/1654

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Windows

Control ID: f6bb7ed9a0da8c67c4160baad47eb98bb5581d570632efa8c7cce745b7778fe4