2.9 Ensure 'Trustworthy' Database Property is set to 'Off'

Information

The TRUSTWORTHY database option allows database objects to access objects in other databases under certain circumstances.

Provides protection from malicious CLR assemblies or extended procedures.

Solution

Execute the following T-SQL statement against the databases (replace

<database_name>

below) returned by the Audit Procedure:

ALTER DATABASE [<database_name>] SET TRUSTWORTHY OFF;

See Also

https://workbench.cisecurity.org/benchmarks/14058