4.2 Ensure Example or Test Databases are Not Installed on Production Servers

Information

The default MySQL installation does not contain any example or test databases. However, it is a good idea to review for common example databases and ensure they have been removed from production systems.

Dropping example databases will reduce the attack surface of the MySQL server.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Execute the following SQL statement to drop an example database:

DROP DATABASE <database name>;

See Also

https://workbench.cisecurity.org/benchmarks/20912

Item Details

Category: PLANNING, SYSTEM AND SERVICES ACQUISITION

References: 800-53|PL-8, 800-53|SA-8

Plugin: MySQLDB

Control ID: 3405138f6084a657fef2b7618f18298e09baf0e1f25d777f9fbc84b156421426