3.1.18 Ensure 'debug_print_plan' is disabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The debug_print_plan setting enables printing the execution plan for each executed query. These messages are emitted at the LOG message level. Unless directed otherwise by your organization's logging policy, it is recommended this setting be disabled by setting it to off.

Rationale:

Enabling any of the DEBUG printing variables may cause the logging of sensitive information that would otherwise be omitted based on the configuration of the other logging settings.

Solution

Execute the following SQL statement(s) to disable this setting:

postgres=# alter system set debug_print_plan = 'off';
ALTER SYSTEM
postgres=# select pg_reload_conf();
pg_reload_conf
----------------
t
(1 row)

Default Value:

off

See Also

https://workbench.cisecurity.org/files/4247

Item Details

References: CSCv7|5.1

Plugin: PostgreSQLDB

Control ID: 639bfcbb60c144ba360f5ace63920f2ec0a6c4d6c3662af559ce6f3021c2e187