4.1.4 Disable Database Discovery (DISCOVER_DB)

Information

The DISCOVER_DB parameter specifies if the database will respond to a discovery request from a client. It is recommended that this parameter be set to DISABLE.

Rationale:

Setting the database discovery to disabled can hide a database with sensitive data.

Solution

Connect to the Db2 database

db2 => connect to <dbname>

Run the following command:

db2 => update database configuration using discover_db disable

See Also

https://workbench.cisecurity.org/benchmarks/10752

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Unix

Control ID: 24c886d7852190b955a0fcd90195a9505c870d4e183b0bfaf268717ea3a6a528