6.1.10 Secure WLMADM Authority

Information

The WLMADM authority manages workload objects for a database. Holders of DBADM authority implicitly also hold WLMADM authority.

Rationale:

The WLMADM authority enables creating, altering, dropping, commenting, granting, and revoking access to workload objects for a database.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Revoke any user who should NOT have WLMADM authority:

db2 => REVOKE WLMADM ON DATABASE FROM USER <username>

See Also

https://workbench.cisecurity.org/benchmarks/10752

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: IBM_DB2DB

Control ID: 9627c96bba3192369a878c4d86645dff7099f592b4b4c941daa596e9d4f18f27