2.4 Do Not Reuse Usernames

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Utilizing unique database accounts across applications will reduce the impact of a compromised MySQL account.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Add/Remove users so that each user is only used for one specific purpose. Impact: If a user is reused then a compromise of this user will compromise multiple parts of the system and/or application.

See Also

https://workbench.cisecurity.org/files/1617