The permissions must be restricted to only the owner of the Oracle software and the dba group. Level 1, Scorable NOTE: Change CONTROLFILE to the control_file parameter set in the init.ora file. ref: https://benchmarks.cisecurity.org/tools2/oracle/CIS_Oracle_11g_Benchmark_v1.0.1.pdf, pg 23.