DG0186-ORACLE11 - The database should not be directly accessible from public or unauthorized networks.

Information

Databases often store critical and/or sensitive information used by the organization. For this reason, databases are targeted for attacks by malicious users. Additional protections provided by network defenses that limit accessibility help protect the database and its data from unnecessary exposure and risk.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Do not allow direct connections from users originating from the Internet or other public network to the DBMS.

Include in the System Security Plan for the system whether the DBMS serves public-facing applications or applications serving users from other untrusted networks.

Do not store sensitive or classified data on a DBMS server that serves public-facing applications.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-24449r1_rule, STIG-ID|DG0186-ORACLE11, Vuln-ID|V-15122

Plugin: Windows

Control ID: 5c9605132aabbaa44c479dac94859e922d2a548a7705d487dca3ba20eb2af582