How to STIG MySQL

So you've been handed a MySQL database, a DISA STIG checklist, and orders to secure the server ahead of an upcoming ATO audit.  This is your first MySQL Server STIG, and your last ATO audit if you don't get it right.  Manually performing the checks is taking too long, and the Check Details text in the STIG isn't always clear.  As the hours turn to days, you start asking yourself...

What are my alternatives?

So What Are Your Options to STIG MySQL?

Option 1: Keep Manually Performing STIG Checks

I know this isn't the answer you wanted to hear, but performing these checks manually has its benefits—at first—if you are new to the MySQL STIG routine.

Studying each vulnerability discussion, running each prescribed script manually, and then evaluating the returned results yourself will help you gain the deepest possible understanding of your current MySQL security posture and DISA’s goals for perfecting it.

Consider manually performing these checks several times before you begin scripting your own solutions or shopping for automation tools.

Option 2: Write Your Own Scripts

Once you have a firm grip on the subject matter and can be sure your efforts to speed up the process won't impact the accuracy of your results, you can begin making one of the more tedious aspects of your job a little easier. 

Scripting all of the DISA provided SQL queries to run with one click of a button is easy enough.  Ditto for most of the BASH scripts.  Maybe you can even add some logic of your own to indicate pass/fail for some of those checks, but if you want to go further, you'll need more than just SQL and BASH programming skills.

The biggest hurdle to developing a real automation solution is probably your inability to write your output directly to your DISA checklist. Cutting and pasting results is dull work and prone to error. If you aren't familiar with XML, do yourself a favor and take a class. Extensible Markup Language is the backbone of your MySQL STIG checklist, and you need to know how to interact directly with it if you don't want all your work to end in a long cut/paste session.

You also need additional non-SQL programming skills. The most tedious “manual” checks target objects and settings outside of MySQL. PowerShell and Python are both great choices for tackling these tasks, depending on your operating system, but almost any language will do, especially if you are familiar with it and it can execute in your environment.

If you are coming to MySQL database administration from a background in systems administration, this will be helpful too. Much of the information you will need to gather and evaluate exists in operating and file systems.

Option 3: Supplemental Automation Utility

If you lack the time or expertise necessary to script all these checks yourself, don't give up on automation. DISA maintains a list of helpful tools here.  These are not the only options available, however. The DoD provides guidelines for the kinds of desktop software utilities they deem acceptable.

Those guidelines read, in part:

The Desktop Application STIG version 3, release 1, notes in particular that three [sic] cases for software are acceptable:
  1. A utility that has publicly available source code is acceptable.
  2. A commercial product that incorporates open source software is acceptable because the commercial vendor provides a warranty.
  3. Vendor supported open source software is acceptable.
  4. A utility that comes compiled and has no warranty is not acceptable.
Thus, a program must come with either source code or a warranty; if it has neither, then special dispensation is required, since it is difficult to review, repair, or extend the program either directly or via someone else.

We recommend our own utility, ASSET for MySQL (the Automated SQL Security Evaluation Tool for MySQL), and we believe it's the most complete and accurate supplemental automation tool available for scanning MySQL.  It comes either as a compiled product, with a warranty, or as a vendor supported open-source product (contract required).

How Does ASSET for MySQL Work?

ASSET for MySQL is a vulnerability scanning tool for MySQL servers capable of performing nearly all vulnerability checks for DISA’s MySQL STIG checklist. ASSET for MySQL compiles and evaluates data from both the Operating and File Systems, and MySQL itself.

In only a few minutes, ASSET for MySQL gathers and evaluates relevant data before outputting the results and findings directly to a DISA STIG checklist based on the XCCDF (Extensible Configuration Checklist Description Format). 

Are You Ready to Automate MySQL STIGs with ASSET for MySQL?

If you’re ready to move to an automated MySQL STIG tool, there are two ways to purchase ASSET for MySQL. We offer a 1-Month Single-Seat License,  and a 1-Year Per Domain License.

If you still have questions or special requirements, please feel free to contact us. We are very responsive to special requests that fit our model.