Appropriate staff must be alerted when the amount of storage space used by the SQL Server transaction log file(s) exceeds an organization-defined value.

From Microsoft SQL Server 2012 Database Security Technical Implementation Guide

Part of SRG-APP-000144-DB-000101

Associated with: CCI-000533

SV-85249r1_rule Appropriate staff must be alerted when the amount of storage space used by the SQL Server transaction log file(s) exceeds an organization-defined value.

Vulnerability discussion

It is important for the appropriate personnel to be aware if the system is at risk of failing to record transaction log data. The transaction log is the heart of a SQL Server database. If it fails, processing will stop. It must always have enough available storage space to cope with peak load. Administrators must be warned about abnormally high space consumption soon enough to take corrective action before all space is used up.

Check content

Review system documentation and/or organizational procedures to determine the threshold value for the storage used by the transaction log, above which staff must be alerted. The threshold may be expressed as an absolute quantity, or a percentage of total available space. If this threshold has not been defined, this is a finding. If monitoring software is in use, and has been configured to alert system and database administrators when the threshold is exceeded, this is not a finding. If manual procedures exist for frequently checking the space used and alerting system and database administrators, and there is evidence that the procedures are adhered to, this is not a finding. Otherwise, this is a finding.

Fix text

Decide on, and document, the threshold value for alerting administrators to a shortage of storage for the transaction log. Establish automated or manual monitoring and alerting.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer