SQL Server, the DoD, and Common Criteria
Common Criteria is an international standard for a set of security characteristics, and the U.S. Department of Defense (DoD) Database Security Technical Implementation Guide (STIG) (via the Security Readiness Review for SQL Server) requires it to be enabled. (See DG0084.)
You can turn it on by using sp_configure ("common criteria compliance enabled") or by using SQL Server Management Studio (server properties, security page, options, "Enable Common Criteria compliance" checkbox).
Enabling SQL Server's Common Criteria switch will enable 3 functions:
- Residual Information Protection
- The ability to view login statistics
- Prevention of a column-level GRANT from overriding a table-level DENY
For more details about these functions, see the SQL Server Books Online article here.
If you want to know about Common Criteria evaluations of different SQL Server versions and service pack levels, just go to this page and click on the tabs across the top.
Comments
Anonymous
January 01, 2003
Hi REastman, you're right about the file sizes for C2, which was a major reason for using Common Criteria instead of C2. I should have mentioned that in the post.Anonymous
August 24, 2011
Enabling the C2 Compliance option also grows the trace files to an insane size if you have lots of DB activity.