Control Compliance Suite 11 - Is SQL check "Are permissions assigned to roles rather than users?" reporting false positives?
search cancel

Control Compliance Suite 11 - Is SQL check "Are permissions assigned to roles rather than users?" reporting false positives?

book

Article ID: 164329

calendar_today

Updated On:

Products

Control Compliance Suite Databases MS SQL SRVR Control Compliance Suite Windows

Issue/Introduction

Check 8.2 "Are permissions assigned to roles rather than users?" of the "CIS Security Configuration Benchmark for Microsoft SQL Server 2005 v1.1.1" standard is reporting (many) objects that apparently have permissions directly assigned however when looking at the objects reported there is no sign of permissions directly assigned to that object.

 

no error message as such.

 

Environment

Control Compliance Suite 11.x

Microsoft SQL server 2005

Standard: CIS Security Configuration Benchmark for Microsoft SQL Server 2005 v1.1.1

Check 8.2: "Are permissions assigned to roles rather than users?"

 

Cause

When you directly assign certain privileges to a user at database level (rather than object level) CCS will fail this check reporting one line of evidence for each object that inherited the privileges.

 

Resolution

Looking at the objects themselves, they don't show those assigned privileges. Database level assigned privileges do not seem to show on object level in MS SQL. CCS is correct to highlight the objects with directly assigned privileges, please have a look at database level assigned privileges and correct if need be.