DG0157-ORACLE11 - Remote DBMS administration should be documented and authorized or disabled.

Information

Remote administration may expose configuration and sensitive data to unauthorized viewing during transit across the network or allow unauthorized administrative access to the DBMS to remote users.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Disable remote administration of the DBMS where not required.

Where remote administration of the DBMS is required, develop, document and implement policy and procedures on its use.

Assign remote administration privileges to IAO-authorized personnel only.

Document assignments in the System Security Plan.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-24982r1_rule, STIG-ID|DG0157-ORACLE11, Vuln-ID|V-15651

Plugin: Unix

Control ID: b4d5391503b606ade29aa9469909ae038833c750af79ea5535662dbf52bd622d