Security Requirements

DBSAT output files are sensitive because they may reveal weaknesses in the security posture of your database. To prevent unauthorized access to these files, you must implement the following security guidelines:

  • Ensure that the directories holding these files are secured with the appropriate permissions.
  • Delete the files securely after you implement the recommendations they contain.
  • Share them with others in their (by default) encrypted form.
  • Grant user permissions to the DBSAT user on a short-term basis and revoke these when no longer necessary.

    For more information about DBSAT user privileges, see Collector Prerequisites. For more information about DBSAT best practices, see Best Practices.

Caution:

This tool is intended to assist you in identifying potential sensitive data and vulnerabilities in your system. Further, the output generated by this tool may include potentially sensitive system configuration data and information that could be used by a skilled attacker to penetrate your system. You are solely responsible for ensuring that the output of this tool, including any generated reports, is handled in accordance with your company's policies.