DG0117-ORACLE11 - Administrative privileges should be assigned to database accounts via database roles.

Information

Privileges granted outside the role of the administrative user job function are more likely to go unmanaged or without oversight for authorization. Maintenance of privileges using roles defined for discrete job functions offers improved oversight of administrative user privilege assignments and helps to protect against unauthorized privilege assignment.

Solution

Revoke assigned administrative privileges from database accounts and assign to accounts via roles.

Document roles and assignments in the System Security Plan.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, Rule-ID|SV-24422r2_rule, STIG-ID|DG0117-ORACLE11, Vuln-ID|V-15627

Plugin: OracleDB

Control ID: d938a61a8f530730ecaf3d50a4288218e284310a050a63211521a1a3c2547712