DG0109: DBMS dedicated host - 'Review services running on the SQL host'

Information

ref: DISA DB STIG SQL 2005 V8
ref: Vulnerability Key: V0015146
ref: STIG ID: DG0109-SQLServer9
ref: Severity: Category II
The DBMS should not be operated without authorization on a host system supporting other application services.
In the same way that added security layers can provide a cumulative positive effect on security posture, multiple applications can provide
a cumulative negative effect. A vulnerability and subsequent exploit to one application can lead to an exploit of other applications
sharing the same security context. For example, an exploit to a web server process that leads to unauthorized administrative access to the
host system can most likely lead to a compromise of all applications hosted by the same system. A DBMS not installed on a dedicated host
may pose a threat to and be threatened by other hosted applications. Applications that share a single DBMS may also create risk to one
another. Access controls defined for one application by default may provide access to the other application's database objects or
directories. Any method that provides any level of separation of security context assists in the protection between applications.
ref: U_INS_sqlserver9_v8r1.7_Checklist_20100827.pdf pg. 93