MongoDB Security Checklist
Enable access control and enforce authentication
Enable access control and specify an authentication mechanism — MongoDB’s default mechanism or an existing external framework. Authentication requires every client and server to provide valid credentials before connecting. In clustered deployments, enable authentication on every MongoDB server.
Configure role-based access control
Create a user administrator first, then create additional users — a unique MongoDB user for each person and application that accesses the system.
Create roles that define exactly the access a set of users needs, following the principle of least privilege, then assign users only the roles they need to do their job. A user can be a person or a client application.
Encrypt communication
Configure MongoDB to use TLS/SSL for all incoming and outgoing connections — between
mongod and mongos components, and between every application and MongoDB.
Starting in version 4.0, MongoDB uses the native TLS/SSL OS libraries:
- Windows: Secure Channel (Schannel)
- Linux/BSD: OpenSSL
- macOS: Secure Transport
Note: starting in version 4.0, MongoDB disables TLS 1.0 support on systems where TLS 1.1+ is available.
Encrypt and protect data
Starting with MongoDB Enterprise 3.2, the WiredTiger storage engine’s native Encryption at Rest can encrypt data at the storage layer.
If you’re not using WiredTiger’s encryption at rest, encrypt MongoDB data on each host using file-system, device, or physical encryption, and protect it with file-system permissions — this includes data files, configuration files, audit logs, and key files.
Limit network exposure
Run MongoDB in a trusted network environment, and limit the interfaces on which instances listen for incoming connections — allow only trusted clients to reach those interfaces and ports.
Note: starting with MongoDB 3.6, mongod and mongos bind to localhost by default.
From versions 2.6 to 3.4, only the binaries from the official MongoDB RPM (Red Hat,
CentOS, Fedora, and derivatives) and DEB (Debian, Ubuntu, and derivatives) packages did
this by default.
Audit system activity
Track access and changes to database configuration and data. MongoDB Enterprise includes a system auditing facility that records events like user operations and connection events, permitting forensic analysis and letting administrators verify proper controls.
Run MongoDB with a dedicated user
Run MongoDB processes under a dedicated OS user account, with permission to access data but no unnecessary permissions beyond that.
Run MongoDB with secure configuration options
MongoDB can execute JavaScript for certain server-side operations — mapReduce,
group, and $where. If you don’t use these, disable server-side scripting with the
--noscripting option.
Use only the MongoDB wire protocol in production. Keep input validation enabled — the
wireObjectCheck setting is on by default, ensuring every document stored by mongod
is valid BSON.
Request a Security Technical Implementation Guide (where applicable)
The Security Technical Implementation Guide (STIG) contains security guidelines for deployments within the US Department of Defense. MongoDB Inc. provides its STIG on request where needed.
Consider security standards compliance
For applications needing HIPAA or PCI-DSS compliance, refer to the MongoDB Security Reference Architecture to see how to use MongoDB’s security capabilities to build compliant infrastructure.