1.2 Use Dedicated Least Privileged Account for MySQL Daemon/Service

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

As with any service installed on a host, it can be provided with its own user context. Providing a dedicated user to the service provides the ability to precisely constrain the service within the larger host context.

Solution

Create a user which is only used for running MySQL and directly related processes. This user must not have administrative rights to the system.

See Also

https://benchmarks.cisecurity.org/tools2/mysql/CIS_Oracle_MySQL_Enterprise_Edition_5.6_Benchmark_v1.0.0.pdf

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Unix

Control ID: a476087ea26c7515fe4220ee9af3536a37fc8bc6bbe60c0cf263438ef1d50418