The RSA must have limited access requirements. Granting the RSA domain level privileges negates the purpose of the RSA. Level 1, Scorable Change 'RSA Group' to the Restricted Service Accounts group for your organization. NOTE: Change 'oracleuser' to the Oracle administrator account for your organization. ref: https://benchmarks.cisecurity.org/tools2/oracle/CIS_Oracle_11g_Benchmark_v1.0.1.pdf, pg 5.