DG0021-ORACLE11 - A baseline of database application software should be documented and maintained.

Information

Without maintenance of a baseline of current DBMS application software, monitoring for changes cannot be complete and unauthorized changes to the software can go undetected. Changes to the DBMS executables could be the result of intentional or unintentional actions.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Develop, document and implement DBMS software baseline procedures that include all DBMS software files and directories under the ORACLE_BASE and ORACLE_HOME environment variables and any custom and platform-specific directories.

Generate a list of files, directories and details for the DBMS software configuration baseline.

Update the configuration baseline after new installations, upgrades/updates or maintenance activities that include changes to the baseline software.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-24610r1_rule, STIG-ID|DG0021-ORACLE11, Vuln-ID|V-3806

Plugin: Unix

Control ID: fea38b872bd9ae78434f128bbb1c3c9bd90c805281d486e2badb5cd903e39f6f