{"id":19429,"date":"2019-08-15T19:56:42","date_gmt":"2019-08-15T19:56:42","guid":{"rendered":"https:\/\/www.process.st\/templates\/sql-server-audit-checklist-3\/"},"modified":"2024-02-28T23:55:51","modified_gmt":"2024-02-28T23:55:51","slug":"sql-server-audit-checklist-3","status":"publish","type":"post","link":"https:\/\/www.process.st\/templates\/sql-server-audit-checklist-3\/","title":{"rendered":"SQL Server Audit Checklist"},"content":{"rendered":"<section id=\"introduction\">\n<h2>Introduction:<\/h2>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/rE3UMcA5jCJtDqHON6hM_A.png\" alt=\"Introduction:\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/rE3UMcA5jCJtDqHON6hM_A.png\"> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>Server-side events logs and everything that comes with it can be a big stress.<\/p>\n<p>With SQL Server logging<strong> compliance standards&nbsp;<a href=\"https:\/\/searchsqlserver.techtarget.com\/tip\/Logging-for-security-compliance-in-SQL-Server\" rel=\"nofollow\">tighter than ever<\/a>&nbsp;<\/strong>in the face of recent data security acts such as<span>&nbsp;HIPAA, PCI DSS, and SOX, there is often so much that goes into the preparation for an SQL Server Audit that&nbsp;<strong>it can be confusing to keep track of everything.<\/strong><\/span><span><\/span><\/p>\n<p><span>On the other hand, the SQL Server Audit process has been<a href=\"https:\/\/www.sqlshack.com\/understanding-sql-server-audit\/\" rel=\"nofollow\"> greatly improved<\/a> in recent years by the&nbsp;addition of Extended Events logs, allowing&nbsp;administrators to <strong>audit everything that happens on each server<\/strong>, from large-scale changes to system settings right down to which user modified what specific value in a&nbsp;particular database at any given time.<\/span><\/p>\n<p>But still, despite all of these improvements to the&nbsp;server auditing process, it can still be daunting to get started without a formal process already in place.<\/p>\n<p><span>Alongside events log best practices, there are a number of<strong> related tasks you should be incorporating into any&nbsp;routine server best practice check<\/strong>, like system updates and data encryption.&nbsp;<\/span>These additional checks serve to support the audit process as well as harden overall server security.<\/p>\n<p><strong>This checklist is designed to give you a head-start <\/strong>for preparation ahead of and including an SQL Server Audit. Though we've&nbsp;been rigorous, this checklist is just an example&nbsp;and is by no means exhaustive of every SQL Server security parameter.<\/p>\n<p>Nonetheless, let's dive right in!<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"preparation\">\n<h2>Preparation:<\/h2>\n<\/section>\n<section id=\"record-basic-details\">\n<h2>Record basic details<\/h2>\n<div class=\"text-content\">\n<p>To begin with, record some basic information about yourself (or whoever is performing the server audit).<\/p>\n<p>All of this information goes towards ensuring data security best practices are enforced - it's important to know who had access to what information, and when.&nbsp;<\/p>\n<p>Just <strong>fill out each form field in this task<\/strong> before proceeding with the rest of the checklist.<\/p>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> First name of database admin performing Server Audit <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Last name of database admin performing server audit <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<div class=\"date-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> When was the server audit performed? <\/label> <\/p>\n<div class=\"date-container\">\n    <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-calendar btn-icon\"><\/i> Date will be set here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> MAC address of server being audited <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Static IP address of server being audited <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> What operating system is installed on the server? <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Does the SQL Server store sensitive user data? <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Is the server using SQL Server triggers? <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"system-maintenance\">\n<h2>System maintenance:<\/h2>\n<\/section>\n<section id=\"uninstall-unused-programs-on-windows\">\n<h2>Uninstall unused programs on Windows<\/h2>\n<div class=\"text-content\">\n<p>We're starting with the simple stuff - this kind of cleanup shouldn't take long and helps free up server space.&nbsp;<\/p>\n<p>It's also a good idea in general to <strong>keep only the most necessary software installed on your servers<\/strong>, as every 3rd party install is a potential backdoor for malicious actors.<\/p>\n<p>Here's a quick rundown of the essentials for this task:<\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Open the Control Panel\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Click \"Programs and Features\"\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       3\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Sort by recently used\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       4\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Look for software that hasn't been used in the past month\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       5\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Remove unnecessary programs as you see fit\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"uninstall-unused-programs-on-linux\">\n<h2>Uninstall unused programs on Linux<\/h2>\n<div class=\"text-content\">\n<p><span>Removing unused programs on Linux is very simple. Just <strong>enter the following in the terminal:<\/strong><strong><\/strong><\/span><\/p>\n<pre><span>&nbsp;<\/span><span>sudo apt autoremove<\/span><\/pre>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>Linux systems are designed to keep track of which programs and packages aren't used or depended on, so it can trim the surplus with a simple command.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"install-latest-service-packs-and-patches\">\n<h2>Install latest service packs and patches<\/h2>\n<div class=\"text-content\">\n<p><span>Microsoft distributes bug fixes for all of their products in \"service packs\". <\/span><\/p>\n<p><span>Each pack includes updates for system drivers,&nbsp;system administration tools, and additional components all bundled together for ease of use.&nbsp;<\/span><\/p>\n<p class=\"style-info\"><span>Service packs are cumulative \u2013 you will only ever need to install the most recent.<\/span><\/p>\n<p><span><strong>Check <a href=\"https:\/\/sqlserverupdates.com\/\" rel=\"nofollow\">here<\/a> for all SQL Server updates,<\/strong> and <strong>make sure your system is fully patched.<\/strong><\/span><\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Updates list checked for new service packs\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      New service packs and patches have been applied for SQL Server\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"access-and-privileges\">\n<h2>Access and privileges:<\/h2>\n<\/section>\n<section id=\"check-the-sql-server-privilege-level\">\n<h2>Check the SQL Server privilege level<\/h2>\n<div class=\"text-content\">\n<p>You need to <strong>make sure that the SQL Server is running on the least-privileged local account level.<\/strong><\/p>\n<p class=\"style-warning\">If network services are required, then granting domain-level privileges is acceptable.<\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Check the SQL Server account privilege level\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Evaluate how low the privilege can be made without affecting function\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       3\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Adjust SQL Server privilege levels accordingly\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"clean-up-unused-accounts\">\n<h2>Clean up unused accounts<\/h2>\n<div class=\"text-content\">\n<p>Your task here is to <strong>remove all unused accounts for both Windows and SQL Server. <\/strong><\/p>\n<p>Whether it's because of staff turnover, systems testing, or just plain oversight, old user accounts that are no longer in use present a security threat because they aren't able to be maintained to updated security standards.&nbsp;<\/p>\n<p>As such, they should be regularly purged so that malicious actors can't exploit them. <strong>It's good practice to delete accounts that haven't been used in over a month.<\/strong><\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Unused user accounts removed\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Unused SQL Server accounts removed\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"restrict-group-access\">\n<h2>Restrict group access<\/h2>\n<div class=\"text-content\">\n<p>&nbsp;User groups can be incredibly useful when used properly, making it easy to&nbsp;manage and scale large sets of people.<\/p>\n<p>When poorly managed, they become a security threat and a general nuisance.<\/p>\n<p>You should <strong>carefully monitor which groups have access to what<\/strong>, especially if you use large generic \"Everyone\" groups. Sometimes, cracks in system security can appear through these group access rights, so it's crucial you clamp down on this, and include it in your regular audit process.<\/p>\n<p><strong>Check of these sub-tasks once you've confirmed each of them as true:<\/strong><\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Make sure the \"Everyone\" group cannot access SQL Server install directories\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Ensure group membership audit policy is updated and enforced\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"ensure-login-restrictions-are-applied\">\n<h2>Ensure login restrictions are applied<\/h2>\n<div class=\"text-content\">\n<p>The security of your database depends on your ability to enforce accountability. Your extensive events logging efforts are all in vain if you can't even put a name to an action, should any internal hiccups arise.<\/p>\n<p>That's why it's important to <strong>ensure that login restrictions are in place<\/strong>. Your database admins should be accessing the SQL Servers from <em>company machines only. <\/em><\/p>\n<p>These machines have been set up&nbsp;to comply with specific information security compliance protocols for a reason, and it defeats security protocol best practice to allow random access from unknown external machines, even if the person remotely accessing the network is trusted.<\/p>\n<p><strong>Perform the following sub-tasks and check them off as you go:<\/strong><\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Remote logins are restricted\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Anonymous logins are restricted\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"review-administrator-settings\">\n<h2>Review administrator settings<\/h2>\n<div class=\"text-content\">\n<p>The <strong>administrator account(s) should be renamed and passwords reset<\/strong> regularly.<\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Administrator account names reset\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Administrator account passwords reset\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<div class=\"text-content\">\n<p>While you're at it,<strong> make sure that membership to the local administrator group is restricted to at most two users.&nbsp;<\/strong>Usually, only the database administrator (DBA) will have admin rights in this scenario.<\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Remove all non-essential users from the local administrator group\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"data-protection\">\n<h2>Data protection:<\/h2>\n<\/section>\n<section id=\"encrypt-sensitive-data-files\">\n<h2>Encrypt sensitive data files<\/h2>\n<div class=\"text-content\">\n<p>Encryption allows protecting the underlying database storage files and on-site\/offsite backups from theft. Most encryption algorithms rely on a principle of using a secure \"key\" or password held by the user to secure or \"lock\" the data so that the key is required to access it.<\/p>\n<p>Which encryption algorithm is best for you will depend on your needs and setup, as well as what kind of data needs encrypting. <strong>Follow the sub-checklist tasks below<\/strong> to deploy encryption on your SQL Server database.<\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Choose an encryption algorithm\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Generate a private key\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       3\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Securely store the private key\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       4\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Select which data to encrypt\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       5\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Encrypt the sensitive data\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"remove-unnecessary-shared-folders\">\n<h2>Remove unnecessary shared folders<\/h2>\n<div class=\"text-content\">\n<p>Just as with User Group access, file and folder shares are often overlooked and many unnecessary shares are left sitting wide open for no good reason.<\/p>\n<p>Take the time to review all shared folders on the server, and <strong>remove any that aren't necessary.<\/strong><\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      All unnecessary shares are removed from the server\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Access to required shares is restricted\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       3\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Unnecessary admin shares are removed\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"server-security\">\n<h2>Server security:<\/h2>\n<\/section>\n<section id=\"disable-all-protocols-except-tcpip\">\n<h2>Disable all protocols except TCP\/IP<\/h2>\n<div class=\"text-content\">\n<p>The more protocols that your server is configured to listen and respond to, the more vulnerabilities exist within your network. <strong>Make sure only the necessary protocols are enabled<\/strong>; usually, TCP\/IP is adequate.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Open Server Network Utility\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Expand the Network Configuration node\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       3\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Select \"Protocols\"\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       4\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Right click \"TCP\/IP\" and click \"Properties\"\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       5\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Make sure the only protocol enabled is \"TCP\/IP\"\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<div class=\"text-content\">\n<p>If there are additional protocols which you need to activate for server functionality, you can easily add them to the sub-checklist above by <a href=\"https:\/\/www.process.st\/help\/docs\/editing-templates\/\" rel=\"nofollow\">editing this task in our template editor.<\/a><\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"configure-server-ports\">\n<h2>Configure server ports<\/h2>\n<div class=\"text-content\">\n<p><span>Proper port access configuration, including restrictions are important security measures for any SQL database server.<\/span><\/p>\n<p><span><strong>Make sure that access to all ports on the server is restricted,<\/strong> except for ports configured for SQL Server and database instances.<\/span><\/p>\n<p class=\"style-info\"><span>By default, the ports configured for SQL server and database instances are TCP 1433 and UDP 1434.<\/span><\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Relevant access granted for database server instance ports\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Access to all other ports on the server is restricted\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<div class=\"text-content\">\n<p>For security reasons, it is also important to <strong>make sure that the ports configured with SQL servers are non-default.<\/strong><\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Ensure that SQL server port is non-default\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"events-logs\">\n<h2>Events logs:<\/h2>\n<\/section>\n<section id=\"check-sql-server-login-audit\">\n<h2>Check SQL Server login audit<\/h2>\n<div class=\"text-content\">\n<p>Failed login attempts can indicate a malicious actor is attempting to access the system.<strong> <\/strong><\/p>\n<p>There are <a href=\"https:\/\/docs.microsoft.com\/en-us\/sql\/database-engine\/configure-windows\/server-properties-security-page?view=sql-server-2017\" rel=\"nofollow\">four types<\/a> of SQL Server login auditing to choose from:<\/p>\n<ol>\n<li><strong>None<\/strong><br \/>Turns off login auditing.<\/li>\n<li><strong>Failed logins only<\/strong><br \/>Audits unsuccessful logins only.<\/li>\n<li><strong>Successful logins only<\/strong><br \/>Audits successful logins only.<\/li>\n<li><strong>Both failed and successful logins<\/strong><br \/>Audits all login attempts.<\/li>\n<\/ol>\n<p><strong>Make sure events logs are enabled for all such instances:<\/strong><\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      All failed operating system login attempts are logged\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      All failed actions are logged across the file system\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"check-system-event-log-configuration\">\n<h2>Check system event log configuration<\/h2>\n<div class=\"text-content\">\n<p>Once you've made sure all relevant actions across the network are included in the logs, you should <strong>take measures to ensure that they are being stored properly and securely,<\/strong> and that relevant triggers are enabled for sensitive data log overflows.<\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Event log files have been securely backed up\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Relevant access has been given to the event logs\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       3\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Shut Down mode is enabled for sensitive log overflows\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"check-sql-server-triggers\">\n<h2>Check SQL Server triggers<\/h2>\n<div class=\"text-content\">\n<p><strong>You can use <a href=\"https:\/\/www.apexsql.com\/sql_tools_trigger.aspx\" rel=\"nofollow\">ApexSQL<\/a>&nbsp;to setup SQL Server triggers.<\/strong> This useful tool allows you to capture data changes with information about who exactly made the change, to which specific items in the database, and when.<\/p>\n<p>It also includes logs of application and host login records, all presented in an easily legible central repository table, which can be reported on and exported to a variety of formats.<\/p>\n<p>To create a SQL Server database trigger based audit trail with ApexSQL Trigger, <strong>follow the sub-tasks below:<\/strong><strong><\/strong><\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Start ApexSQL Trigger\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Connect to the database to audit\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       3\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      In the main grid, select the tables you want to monitor\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/gHu23e6IrNEztoWymp1BnQ.png\" alt=\"Credit to SQLShack for the image.\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/gHu23e6IrNEztoWymp1BnQ.png\"> <\/a><figcaption>\n     Credit to SQLShack for the image.<br \/>\n   <\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      In the Columns pane, select the columns you want to monitor\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Click \"Create triggers\"\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       3\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Click \"Execute\" or press the \"F5\" key to finalize\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"create-a-new-sql-server-audit\">\n<h2>Create a new SQL Server Audit<\/h2>\n<div class=\"text-content\">\n<p>We're almost done - the next step is to <strong>create an SQL Server Audit object using <a href=\"https:\/\/docs.microsoft.com\/en-us\/sql\/ssms\/sql-server-management-studio-ssms?view=sql-server-2017\" rel=\"nofollow\">SQL Server Management Studio<\/a><\/strong>, a configurable tool for managing all kinds of server events.<\/p>\n<p>This process can get a bit involved, but we've outlined all of the important steps for you already. Just make sure you <strong>follow each sub-task in the sub-checklists below<\/strong> and you'll have your Audit set up in no time.<\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Expand the \"Security\" menu\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Right-click \"Audits in SSMS\"\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       3\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Select \"New Audit\"\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       4\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Assign a name to the audit\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       5\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Choose how you want the audit logs to be stored\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       6\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Choose location of the output audit file\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       7\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Click \"Ok\"\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<div class=\"text-content\">\n<p>Your newly created audit should now appear in the \"Audits\" section of the Object Explorer window. It's disabled by default, so you'll want to go ahead and<strong> enable it.<\/strong><\/p>\n<\/p><\/div>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/ovJWlNuKUpQuho3-VhtG0w.png\" alt=\"Create a new SQL Server Audit\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/ovJWlNuKUpQuho3-VhtG0w.png\"> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>Your server audit should now be all set up.<\/p>\n<p><strong>Before you finish with this checklist,<\/strong> the results of the audit might have triggered an automatic server shutdown for security reasons. If that's the case, it will need to be flagged for restart manually.<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Was the server forced to shut down by an SQL Audit trigger? <\/label><br \/>\n   <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"flag-the-server-for-restart\">\n<h2>Flag the server for restart<\/h2>\n<div class=\"text-content\">\n<p>If the SQL Server has been forcefully shut down as a result of an SQL Audit, normal startup will be disabled.&nbsp;<\/p>\n<p>You need to <strong>manually enable a server restart<\/strong>, which can be done by adding&nbsp;the \"-m\" trace flag to single user mode startup configuration.&nbsp;<\/p>\n<p><strong>Follow these sub-tasks<\/strong> to change the server settings and enable a restart:<\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Open the SQL Server Configuration Manager\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Select your server instance\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       3\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Select \"Properties\"\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       4\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Go to the \"Startup Parameters\" tab\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       5\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Add the \"-m\" trace flag to single user startup mode configuration\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"sources\">\n<h2>Sources:<\/h2>\n<div class=\"text-content\">\n<ul>\n<li><a href=\"https:\/\/www.enclavesecurity.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Enclave Security<\/a> - <a href=\"https:\/\/www.enclavesecurity.com\/checklists-a-day-microsoft-sql-server-audit-checklists-week-in-review-april-12-2010\/\" rel=\"nofollow\">SQL Server Audit Process<\/a><\/li>\n<li><a href=\"https:\/\/medium.com\" rel=\"nofollow noopener\" target=\"_blank\">Medium<\/a> - <a href=\"https:\/\/medium.com\/sqladmin\/all-in-one-sql-server-security-audit-script-53b226a51196\" rel=\"nofollow\">All-In-One Server Audit Script<\/a><\/li>\n<li><a href=\"https:\/\/www.microsoft.com\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft<\/a> - <a href=\"https:\/\/docs.microsoft.com\/en-us\/previous-versions\/msp-n-p\/ff648235(v=pandp.10)\" rel=\"nofollow noopener\" target=\"_blank\">SQL Server Audit Bes Practice Checklist<\/a><\/li>\n<li><a href=\"https:\/\/technet.microsoft.com\/en-us\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft Technet<\/a> - <a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/cc966456.aspx\" rel=\"nofollow\">Server Security Best Practice Checklist<\/a><\/li>\n<li><a href=\"https:\/\/searchsqlserver.techtarget.com\/\" rel=\"nofollow noopener\" target=\"_blank\">TechTarget<\/a> - <a href=\"https:\/\/searchsqlserver.techtarget.com\/feature\/SQL-Server-security-test-checklist\" rel=\"nofollow\">Server SQL Security Checklist<\/a><\/li>\n<li><a href=\"https:\/\/bradmcgehee.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Brad McGehee<\/a> - <a href=\"https:\/\/bradmcgehee.com\/2010\/09\/14\/sql-server-security-checklist\/\" rel=\"nofollow\">SQL Server Security Best Practices<\/a><\/li>\n<li><a href=\"https:\/\/solutioncenter.apexsql.com\/\" rel=\"nofollow noopener\" target=\"_blank\">ApexSQL<\/a> - <a href=\"https:\/\/solutioncenter.apexsql.com\/what-is-change-tracking-and-how-to-set-it-up\/\" rel=\"nofollow\">What is SQL Server Tracking and How to Set It Up<\/a><\/li>\n<li><a href=\"https:\/\/www.sqlshack.com\/\" rel=\"nofollow noopener\" target=\"_blank\">SQLShack<\/a> - <a href=\"https:\/\/www.sqlshack.com\/understanding-sql-server-audit\/\" rel=\"nofollow\">Understanding the SQL Server Audit<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"related-checklists\">\n<h2>Related checklists:<\/h2>\n<div class=\"text-content\">\n<ul>\n<li><a href=\"https:\/\/www.process.st\/templates\/inventory-management-process\/\" rel=\"nofollow noopener\" target=\"_blank\">Inventory Management Process<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/network-security-management\/\" rel=\"nofollow noopener\" target=\"_blank\">Network Security Management<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/client-data-backup-best-practices\/\" rel=\"nofollow noopener\" target=\"_blank\">Client Data Backup Best Practices<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/computer-maintenance-guide\/\" rel=\"nofollow noopener\" target=\"_blank\">Computer Maintenance Guide<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/ubuntu-server-setup-process\/\" rel=\"nofollow noopener\" target=\"_blank\">Server Setup Process<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/virtual-private-server-setup\/\" rel=\"nofollow noopener\" target=\"_blank\">Virtual Private Server Setup<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/it-support-process\/\" rel=\"nofollow noopener\" target=\"_blank\">IT Support Process<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/helpdesk-management\/\" rel=\"nofollow noopener\" target=\"_blank\">Helpdesk Management<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/server-maintenance-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Server Maintenance Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/information-security-incident-response\/\" rel=\"nofollow noopener\" target=\"_blank\">Information Security Incident Response<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/server-security-checklist\" rel=\"nofollow noopener\" target=\"_blank\">Server Security Checklist<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Introduction: Server-side events logs and everything that comes with it can be a big stress. With SQL Server logging compliance standards&nbsp;tighter than ever&nbsp;in the face of recent data security acts such as&nbsp;HIPAA, PCI DSS, and SOX, there is often so much that goes into the preparation for an SQL Server Audit that&nbsp;it can be confusing [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":2762,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ep_exclude_from_search":false,"cover_icon_emoji":"","cover_icon_url":"","tasks_count":"27","template_description":"Run this checklist as part of a routine SQL Server Audit to ensure compliance standards are met.","template_id":"tfSGVhryR1cU_eQs9lxNsA","task_0":"Introduction:","task_slug_0":"introduction","task_1":"Preparation:","task_slug_1":"preparation","task_2":"Record basic details","task_slug_2":"record-basic-details","task_3":"System maintenance:","task_slug_3":"system-maintenance","task_4":"Uninstall unused programs on Windows","task_slug_4":"uninstall-unused-programs-on-windows","task_5":"Uninstall unused programs on Linux","task_slug_5":"uninstall-unused-programs-on-linux","task_6":"Install latest service packs and patches","task_slug_6":"install-latest-service-packs-and-patches","task_7":"Access and privileges:","task_slug_7":"access-and-privileges","task_8":"Check the SQL Server privilege level","task_slug_8":"check-the-sql-server-privilege-level","task_9":"Clean up unused accounts","task_slug_9":"clean-up-unused-accounts","task_10":"Restrict group access","task_slug_10":"restrict-group-access","task_11":"Ensure login restrictions are applied","task_slug_11":"ensure-login-restrictions-are-applied","task_12":"Review administrator settings","task_slug_12":"review-administrator-settings","task_13":"Data protection:","task_slug_13":"data-protection","task_14":"Encrypt sensitive data files","task_slug_14":"encrypt-sensitive-data-files","task_15":"Remove unnecessary shared folders","task_slug_15":"remove-unnecessary-shared-folders","task_16":"Server security:","task_slug_16":"server-security","task_17":"Disable all protocols except TCP\/IP","task_slug_17":"disable-all-protocols-except-tcpip","task_18":"Configure server ports","task_slug_18":"configure-server-ports","task_19":"Events logs:","task_slug_19":"events-logs","task_20":"Check SQL Server login audit","task_slug_20":"check-sql-server-login-audit","task_21":"Check system event log configuration","task_slug_21":"check-system-event-log-configuration","task_22":"Check SQL Server triggers","task_slug_22":"check-sql-server-triggers","task_23":"Create a new SQL Server Audit","task_slug_23":"create-a-new-sql-server-audit","task_24":"Flag the server for restart","task_slug_24":"flag-the-server-for-restart","task_25":"Sources:","task_slug_25":"sources","task_26":"Related checklists:","task_slug_26":"related-checklists","task_27":"","task_slug_27":"","task_28":"","task_slug_28":"","task_29":"","task_slug_29":"","task_30":"","task_slug_30":"","task_31":"","task_slug_31":"","task_32":"","task_slug_32":"","task_33":"","task_slug_33":"","task_34":"","task_slug_34":"","task_35":"","task_slug_35":"","task_36":"","task_slug_36":"","task_37":"","task_slug_37":"","task_38":"","task_slug_38":"","task_39":"","task_slug_39":"","task_40":"","task_slug_40":"","task_41":"","task_slug_41":"","task_42":"","task_slug_42":"","task_43":"","task_slug_43":"","task_44":"","task_slug_44":"","task_45":"","task_slug_45":"","task_46":"","task_slug_46":"","task_47":"","task_slug_47":"","task_48":"","task_slug_48":"","task_49":"","task_slug_49":"","task_50":"","task_slug_50":"","task_51":"","task_slug_51":"","task_52":"","task_slug_52":"","task_53":"","task_slug_53":"","task_54":"","task_slug_54":"","task_55":"","task_slug_55":"","task_56":"","task_slug_56":"","task_57":"","task_slug_57":"","task_58":"","task_slug_58":"","task_59":"","task_slug_59":"","task_60":"","task_slug_60":"","task_61":"","task_slug_61":"","task_62":"","task_slug_62":"","task_63":"","task_slug_63":"","task_64":"","task_slug_64":"","task_65":"","task_slug_65":"","task_66":"","task_slug_66":"","task_67":"","task_slug_67":"","task_68":"","task_slug_68":"","task_69":"","task_slug_69":"","task_70":"","task_slug_70":"","task_71":"","task_slug_71":"","task_72":"","task_slug_72":"","task_73":"","task_slug_73":"","task_74":"","task_slug_74":"","task_75":"","task_slug_75":"","task_76":"","task_slug_76":"","task_77":"","task_slug_77":"","task_78":"","task_slug_78":"","task_79":"","task_slug_79":"","task_80":"","task_slug_80":"","task_81":"","task_slug_81":"","task_82":"","task_slug_82":"","task_83":"","task_slug_83":"","task_84":"","task_slug_84":"","task_85":"","task_slug_85":"","task_86":"","task_slug_86":"","task_87":"","task_slug_87":"","task_88":"","task_slug_88":"","task_89":"","task_slug_89":"","task_90":"","task_slug_90":"","task_91":"","task_slug_91":"","task_92":"","task_slug_92":"","task_93":"","task_slug_93":"","task_94":"","task_slug_94":"","task_95":"","task_slug_95":"","task_96":"","task_slug_96":"","task_97":"","task_slug_97":"","task_98":"","task_slug_98":"","task_99":"","task_slug_99":"","footnotes":""},"categories":[7],"tags":[],"class_list":["post-19429","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-miscellaneous"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/19429","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/comments?post=19429"}],"version-history":[{"count":0,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/19429\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media\/2762"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media?parent=19429"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/categories?post=19429"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/tags?post=19429"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}