DG0107-ORACLE11 - Sensitive data is stored in the database and should be identified in the System Security Plan and AIS Functional Architecture documentation.

Information

A DBMS that does not have the correct confidentiality level identified or any confidentiality level assigned is not being secured at a level appropriate to the risk it poses.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Include identification of any sensitive data in the AIS Functional Architecture and the System Security Plan.

Include data that appear to be sensitive with a discussion as to why it is not marked as such.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-24710r1_rule, STIG-ID|DG0107-ORACLE11, Vuln-ID|V-15144

Plugin: Windows

Control ID: cb1922d46d1ac02dc236380f239655f46b0b3425c0e9c7f6327094e8ea2d3c8f