1.2 Use Dedicated Least Privileged Account for MySQL Daemon/Service

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

As with any service installed on a host, it can be provided with its own user context. Providing a dedicated user to the service provides the ability to precisely constrain the service within the larger host context.

Solution

Create a user which is only used for running MySQL and directly related processes. This user must not have administrative rights to the system.

See Also

https://benchmarks.cisecurity.org/tools2/mysql/CIS_Oracle_MySQL_Community_Server_5.6_Benchmark_v1.0.0.pdf

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Windows

Control ID: 86b897c5a1d5e1be01e21c3eaf4409d771f38470a0cbc1050605c01313db07c5