DG0153-ORACLE11 - DBA roles assignments should be assigned and authorized by the IAO.

Information

The DBA role and associated privileges provide complete control over the DBMS operation and integrity. DBA role assignment without authorization could lead to the assignment of these privileges to untrusted and untrustworthy persons and complete compromise of DBMS integrity.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Develop, document and implement procedures to ensure all DBA role assignments are authorized and assigned by the IAO.

Include methods that provide evidence of approval in the procedures.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

References: CAT|III, Rule-ID|SV-24979r1_rule, STIG-ID|DG0153-ORACLE11, Vuln-ID|V-15149

Plugin: OracleDB

Control ID: 4a243f9ac04a5df2981bf3456a8dd0cc11908c75cda96446c44cc100e354eb18