SQL2-00-024100 - The Database Master Key must be encrypted by the Service Master Key where required.

Information

When not encrypted by the Service Master Key, system administrators or application administrators may access and use the Database Master Key to view sensitive data that they are not authorized to view. Where alternate encryption means are not feasible, encryption by the Service Master Key may be necessary. To help protect sensitive data from unauthorized access by DBAs, mitigations may be in order. Mitigations may include automatic alerts or other audit events when the Database Master Key is accessed outside of the application or by a DBA account.

Solution

Where possible, encrypt the Database Master Key with a password known only to the application administrator.
Where not possible, configure additional audit events or alerts to detect unauthorized access to the Database Master Key by users not authorized to view sensitive data.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_SQL_Server_2012_V1R20_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28, CAT|II, CCI|CCI-001199, Rule-ID|SV-53944r3_rule, STIG-ID|SQL2-00-024100, Vuln-ID|V-41415

Plugin: MS_SQLDB

Control ID: 5d2295aed6c0c060c2d63b2d6f618cfa843cfac645f059454d351c236b71e337