DG0138-ORACLE11 - Access grants to sensitive data should be restricted to authorized user roles.

Information

Unauthorized access to sensitive data may compromise the confidentiality of personnel privacy, threaten national security or compromise a variety of other sensitive operations. Access controls are best managed by defining requirements based on distinct job functions and assigning access based on the job function assigned to the individual user.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Define, document and implement all sensitive data access controls based on job function in the System Security Plan.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-24798r1_rule, STIG-ID|DG0138-ORACLE11, Vuln-ID|V-15642

Plugin: OracleDB

Control ID: dbdde42e5dc6e922c070d0973330823ada41d08f4787c07d40482d9975c4be4f