1.1.1 SQL Servers accessed via Internet

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Level 1, Not Scorable
If the SQL Server is being accessed via the Internet, place the SQL Server inside a DMZ
Deploying SQL behind a firewall will reduce the remote attack surface of the underlying OS and SQL related services.
Perform a network audit to determine if your SQL Server resides inside a DMZ with the web server.
ref. https://benchmarks.cisecurity.org/tools2/sqlserver/CIS_Microsoft_SQL_Server_2005_Benchmark_v2.0.0.pdf, pg 13.
Note: Nessus has not performed this query, and this check is only provided for informational purposes.