2.4 Do Not Reuse Usernames

Information

Database user accounts should not be reused for multiple applications or users.

Rationale:

Utilizing unique database accounts across applications will reduce the impact of a compromised MySQL account. If a user is reused, then a compromise of this user will compromise multiple parts of the system and/or application.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Add/Remove users so that each user is only used for one specific purpose.

See Also

https://workbench.cisecurity.org/benchmarks/16527

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2, CSCv7|4.3

Plugin: MySQLDB

Control ID: 7f323fd94c8dcaa79c7d98dd6912a6c9353b1ab3639b14028eee9c2aa2e4f4e5