2.10 Ensure Unnecessary SQL Server Protocols are set to 'Disabled'

Information

SQL Server supports Shared Memory, Named Pipes, and TCP/IP protocols. However, SQL Server should be configured to use the bare minimum required based on the organization's needs.

Rationale:

Using fewer protocols minimizes the attack surface of SQL Server and, in some cases, can protect it from remote attacks.

Impact:

The Database Engine (MSSQL and SQLAgent) services must be stopped and restarted for the change to take effect.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Open SQL Server 2022 Configuration Manager; go to the SQL Server Network Configuration. Ensure that only required protocols are enabled. Disable protocols not necessary.

Default Value:

By default, TCP/IP and Shared Memory protocols are enabled on all commercial editions.

See Also

https://workbench.cisecurity.org/benchmarks/12777

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2

Plugin: Windows

Control ID: 01303b978c45452c9eee7410f9b294414fc74cd473233328a18907f2cfc7d4c3