Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-67905 | SQL4-00-034200 | SV-82395r1_rule | Medium |
Description |
---|
Having unnecessary protocols enabled exposes the system to avoidable threats. In a typical installation, only TCP/IP will be required. |
STIG | Date |
---|---|
MS SQL Server 2014 Instance Security Technical Implementation Guide | 2017-07-19 |
Check Text ( C-68475r1_chk ) |
---|
Review the system security plan to determine the communication protocols used by the SQL Server instance. Open SQL Server Configuration Manager from the Windows Start menu or by entering "SQLServerManager12.msc" in a Command Prompt window or in the Run dialog box. Select SQL Server Network Configuration >> Protocols for If any that are not required are shown as enabled, this is a finding. |
Fix Text (F-74021r1_fix) |
---|
In SQL Server Configuration Manager, right-click on each enabled protocol that is not required. Select Disabled. Close SQL Server Configuration Manager. Restart SQL Server. |