question

Bugmesh avatar image
Bugmesh asked

Audit ID to STIG ID cross reference

I am working on a reference document to help the team be proactive instead of reactive when it comes to security. I created a table with the following columns **STIG_ID**, ID from Security Technical Implementation Guides **TITLE**, Title of the STIG **QUERY_TXT,** The Query to identify any findings **EXPECTED**, What result set to expect **RISK,** STIG Risk Category **VERSION**, Which version of SQL Server it is related to **AUDIT_CAT**, What SQL Server Audit category applies **FIX,** What is the remeiation **DBProtect_ID** The corresponing DBProtect_ID XREF to STIG **REF_ID** Unique ID used for Fulltext index. Does anyone know of a source for cross referencing Audit_ID (category) with the STIG_Id? I was able to figure out the DBPortect XREF. but would appreciate any assistance someone might be able to provide. Thank you for your assitance and support
databasesecurityaudi
10 |1200

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.

1 Answer

·
Bugmesh avatar image
Bugmesh answered
I created an Xref that includes the STIG_ID, The DBProtect_ID, RISK, DBMS Version, The query to run on your server to validate the DBProtect finding, expected results, and then the query or process needed to resolve the issue. It will allow our team to be proactive and stay out ahead of any DBProtect scans that the security section may decide to run,
10 |1200

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.

Write an Answer

Hint: Notify or tag a user in this post by typing @username.

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.