2.10 Ensure Unnecessary SQL Server Protocols are set to 'Disabled'

Information

SQL Server supports Shared Memory, Named Pipes, and TCP/IP protocols. However, SQL Server should be configured to use the bare minimum required based on the organization's needs.

Using fewer protocols minimizes the attack surface of SQL Server and, in some cases, can protect it from remote attacks.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Open SQL Server Configuration Manager ; go to the SQL Server Network Configuration Ensure that only required protocols are enabled. Disable protocols not necessary.

Impact:

The Database Engine (MSSQL and SQLAgent) services must be stopped and restarted for the change to take effect.

See Also

https://workbench.cisecurity.org/benchmarks/14058

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2

Plugin: MS_SQLDB

Control ID: aefdd133e17bce9f05df08934ec1c02ec3b450107debae560b1866bdb4317be5