UCF STIG Viewer Logo

The DBMS must associate and maintain security labels when exchanging information between systems.


Overview

Finding ID Version Rule ID IA Controls Severity
V-32506 SRG-APP-000203-DB-000146 SV-42843r1_rule Medium
Description
When data is exchanged between information systems, the security attributes associated with said data needs to be maintained. Security attributes are an abstraction representing the basic properties or characteristics of an entity with respect to safeguarding information, typically associated with internal data structures (e.g., records, buffers, files) within the information system and used to enable the implementation of access control and flow control policies, reflect special dissemination, handling or distribution instructions, or support other aspects of the information security policy. Security attributes may be explicitly or implicitly associated with the information contained within the information system. If database security labels are not maintained as information moves between systems, handling instructions can be lost and data can be accidentally distributed to unauthorized individuals.
STIG Date
Database Security Requirements Guide 2012-07-02

Details

Check Text ( C-40944r1_chk )
Check DBMS settings to verify security labels are maintained as data moves between systems. If security labels are not maintained as data moves between systems, this is a finding.
Fix Text (F-36421r1_fix)
Configure DBMS settings to maintain security labels as data is passed over connections to other databases and systems.