4.2 Ensure Example or Test Databases are Not Installed on Production Servers

Information

The default MySQL installation does not contain any example or test databases. However, it is a good idea to review for common example databases and ensure they have been removed from production systems.

Rationale:

Dropping example databases will reduce the attack surface of the MySQL server.

Solution

Execute the following SQL statement to drop an example database:

DROP DATABASE <database name>;

See Also

https://workbench.cisecurity.org/files/3859

Item Details

Category: PLANNING, SYSTEM AND SERVICES ACQUISITION

References: 800-53|PL-8, 800-53|SA-8

Plugin: MySQLDB

Control ID: 8c96f03f8099f149c567393508e5f172f2ef65fc1918362d599ea5c5cfd2723c