1.14.2 Restrict access to backup files to System Administrators

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Level 1, Scorable
Delete or secure old setup files. Protect files in the %ProgramFiles%\Microsoft SQL Server\MSSQL.X\MSSQL\Install, e.g., sqlstp.log,
sqlsp.log and setup.iss. X represents the installations of various SQL Server installs due to the fact that multiple instances of SQL
Server or SQL Express can be installed.
If the current system was upgraded from SQL Server version 2000, check setup.iss in the %SystemRoot% folder and the sqlstp.log in the
Windows Temp folder for passwords.
Navigate to the %ProgramFiles%\Microsoft SQL Server\MSSQL.X\MSSQL\Install directory to review the folder permissions.
ref. https://benchmarks.cisecurity.org/tools2/sqlserver/CIS_Microsoft_SQL_Server_2005_Benchmark_v2.0.0.pdf, pg 85.