3.7 Ensure 'PASSWORD_VERIFY_FUNCTION' Is Set for All Profiles

Information

The PASSWORD_VERIFY_FUNCTION determines password settings requirements when a user password is changed at the SQL command prompt. It should be set for all profiles. Note that this setting does not apply for users managed by the Oracle password file.

Rationale:

Through Oracle database profiles, password complexity rules (mixed cases with digits and special characters), blocking of simple combinations, and enforcing change/history settings can potentially thwart unauthorized logins by an unauthorized user.

Solution

Create a custom password verification function which fulfills the password requirements of the organization.

See Also

https://workbench.cisecurity.org/benchmarks/11760

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: OracleDB

Control ID: 1daae7362152f0cef44565836f732fd44bd44cfe2c99583485d761897fff7d02