CIS Oracle Server 11g R2 DB v2.2.0

Audit Details

Name: CIS Oracle Server 11g R2 DB v2.2.0

Updated: 6/27/2023

Authority: CIS

Plugin: OracleDB

Revision: 1.0

Estimated Item Count: 119

File Details

Filename: CIS_Oracle_Server_11g_R2_Database_v2.2.0.audit

Size: 129 kB

MD5: 4e539a1abed8671ee537b26470b108c3
SHA256: 2bb50cbc041a3965410aec562fd8e21f16b8330a27c21204483a7109f17035b3

Audit Items

DescriptionCategories
1.1 Ensure the Appropriate Version/Patches for Oracle Software Is Installed - Patches
1.1 Ensure the Appropriate Version/Patches for Oracle Software Is Installed - Version
1.2 Ensure All Default Passwords Are Changed

IDENTIFICATION AND AUTHENTICATION

1.3 Ensure All Sample Data And Users Have Been Removed
2.2.1 Ensure 'AUDIT_SYS_OPERATIONS' Is Set to 'TRUE'
2.2.2 Ensure 'AUDIT_TRAIL' Is Set to 'OS', 'DB', 'XML', 'DB,EXTENDED', or 'XML,EXTENDED'
2.2.3 Ensure 'GLOBAL_NAMES' Is Set to 'TRUE'
2.2.4 Ensure 'LOCAL_LISTENER' Is Set Appropriately
2.2.5 Ensure 'O7_DICTIONARY_ACCESSIBILITY' Is Set to 'FALSE'
2.2.6 Ensure 'OS_ROLES' Is Set to 'FALSE'
2.2.7 Ensure 'REMOTE_LISTENER' Is Empty
2.2.8 Ensure 'REMOTE_LOGIN_PASSWORDFILE' Is Set to 'NONE'
2.2.9 Ensure 'REMOTE_OS_AUTHENT' Is Set to 'FALSE'
2.2.10 Ensure 'REMOTE_OS_ROLES' Is Set to 'FALSE'
2.2.11 Ensure 'UTIL_FILE_DIR' Is Empty
2.2.12 Ensure 'SEC_CASE_SENSITIVE_LOGON' Is Set to 'TRUE'
2.2.13 Ensure 'SEC_MAX_FAILED_LOGIN_ATTEMPTS' Is Set to '10'
2.2.14 Ensure 'SEC_PROTOCOL_ERROR_FURTHER_ACTION' Is Set to 'DELAY,3' or 'DROP,3'

ACCESS CONTROL

2.2.15 Ensure 'SEC_PROTOCOL_ERROR_TRACE_ACTION' Is Set to 'LOG'
2.2.16 Ensure 'SEC_RETURN_SERVER_RELEASE_BANNER' Is Set to 'FALSE'
2.2.17 Ensure 'SQL92_SECURITY' Is Set to 'TRUE'
2.2.18 Ensure '_TRACE_FILES_PUBLIC' Is Set to 'FALSE'
2.2.19 Ensure 'RESOURCE_LIMIT' Is Set to 'TRUE'
3.1 Ensure 'FAILED_LOGIN_ATTEMPTS' Is Less than or Equal to '5'
3.2 Ensure 'PASSWORD_LOCK_TIME' Is Greater than or Equal to '1'
3.3 Ensure 'PASSWORD_LIFE_TIME' Is Less than or Equal to '90'
3.4 Ensure 'PASSWORD_REUSE_MAX' Is Greater than or Equal to '20'

IDENTIFICATION AND AUTHENTICATION

3.5 Ensure 'PASSWORD_REUSE_TIME' Is Greater than or Equal to '365'

IDENTIFICATION AND AUTHENTICATION

3.6 Ensure 'PASSWORD_GRACE_TIME' Is Less than or Equal to '5'
3.7 Ensure 'DBA_USERS.PASSWORD' Is Not Set to 'EXTERNAL' for Any User

IDENTIFICATION AND AUTHENTICATION

3.8 Ensure 'PASSWORD_VERIFY_FUNCTION' Is Set for All Profiles
3.9 Ensure 'SESSIONS_PER_USER' Is Less than or Equal to '10'
3.10 Ensure No Users Are Assigned the 'DEFAULT' Profile
4.1.1 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'DBMS_ADVISOR'
4.1.2 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'DBMS_CRYPTO'
4.1.3 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'DBMS_JAVA'
4.1.4 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'DBMS_JAVA_TEST'
4.1.5 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'DBMS_JOB'
4.1.6 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'DBMS_LDAP'
4.1.7 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'DBMS_LOB'
4.1.8 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'DBMS_OBFUSCATION_TOOLKIT'
4.1.9 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'DBMS_RANDOM'
4.1.10 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'DBMS_SCHEDULER'
4.1.11 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'DBMS_SQL'
4.1.12 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'DBMS_XMLGEN'
4.1.13 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'DBMS_XMLQUERY'
4.1.14 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'UTL_FILE'
4.1.15 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'UTL_INADDR'
4.1.16 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'UTL_TCP'
4.1.17 Ensure 'EXECUTE' Is Revoked from 'PUBLIC' on 'UTL_MAIL'