7.1 Secure SYSADM authority - SYSADM Group Members

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The sysadm_group parameter defines the system administrator group (SYSADM) authority. It is recommended that the sysadm_group group contains authorized users only.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Define a valid group name for the SYSADM group.
1. Attach to the DB2 instance.
db2 => attach to $DB2INSTANCE
2. Run the following command from the DB2 command window-
db2 => update database manager configuration using sysadm_group <sys adm group name>

See Also

https://workbench.cisecurity.org/files/162