2.2.4 Ensure 'OS_ROLES' Is Set to 'FALSE'

Information

The os_roles setting permits externally created groups to be applied to database management.

Rationale:

Allowing the OS to use external groups for database management could cause privilege overlaps and generally weaken security.

Solution

To remediate this setting, execute the following SQL statement.

ALTER SYSTEM SET OS_ROLES = FALSE SCOPE = SPFILE;

See Also

https://workbench.cisecurity.org/benchmarks/11760

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: OracleDB

Control ID: d7e713484e3a7ad6cc84682a32c482245b324903d724f15372e86cf6f6b770c6