4.2 Ensure Example or Test Databases are Not Installed on Production Servers

Information

The default MySQL installation does not contain any example or test databases. However, it is a good idea to review for common example databases and ensure they have been removed from production systems.

Rationale:

Dropping example databases will reduce the attack surface of the MySQL server.

Solution

Execute the following SQL statement to drop an example database:

DROP DATABASE <database name>;

See Also

https://workbench.cisecurity.org/files/3859

Item Details

Category: PLANNING, SYSTEM AND SERVICES ACQUISITION

References: 800-53|PL-8, 800-53|SA-8

Plugin: MySQLDB

Control ID: 43e13aa104ce7aa64c855d3e1e9797ecd1bcd3ce61cae86734cdd477698af7d3