Item Search

NameAudit NamePluginCategory
DG0031-ORACLE11 - Transaction logs should be periodically reviewed for unauthorized modification of data.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0032-ORACLE11 - Audit records should be restricted to authorized individuals - 'AUD$ table access is restricted'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0065-ORACLE11 - DBMS authentication should require use of a DoD PKI certificate.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DG0071-ORACLE11 - New passwords must be required to differ from old passwords by more than four characters - 'PASSWORD_VERIFY_FUNCTION is not set to NULL or DEFAULT'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0074-ORACLE11 - Unapproved inactive or expired database accounts should not be found on the database.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0075-ORACLE11 - Unauthorized database links should not be defined and active - 'No external database links exist'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0076-ORACLE11 - Sensitive information from production database exports must be modified before import to a development database.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0078-ORACLE11 - Each database user, application or process should have an individually assigned account.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0080-ORACLE11 - Application user privilege assignment should be reviewed monthly or more frequently to ensure compliance with least privilege and documented policy.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0091-ORACLE11 - Custom and GOTS application source code stored in the database should be protected with encryption or encoding.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

SYSTEM AND COMMUNICATIONS PROTECTION

DG0105-ORACLE11 - DBMS application user roles should not be assigned unauthorized privileges.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0116-ORACLE11 - Database privileged role assignments should be restricted to IAO-authorized DBMS accounts.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DG0119-ORACLE11 - DBMS application users should not be granted administrative privileges to the DBMS.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DG0124-ORACLE11 - Use of DBA accounts should be restricted to administrative activities.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0125-ORACLE11 - DBMS account passwords should be set to expire every 60 days or more frequently - 'Database password expiration < 60 days'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

IDENTIFICATION AND AUTHENTICATION

DG0127-ORACLE11 - DBMS account passwords should not be set to easily guessed words or values - 'limit'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0127-ORACLE11 - DBMS account passwords should not be set to easily guessed words or values - 'profile'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0135-ORACLE11 - Users should be alerted upon login of previous successful connections or unsuccessful attempts to access their account.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0138-ORACLE11 - Access grants to sensitive data should be restricted to authorized user roles.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0141-ORACLE11 - Attempts to bypass access controls should be audited.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

AUDIT AND ACCOUNTABILITY

DG0145-ORACLE11 - Audit records should contain required information.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

AUDIT AND ACCOUNTABILITY

DG0146-ORACLE11 - Audit records should include the reason for blacklisting or disabling DBMS connections or accounts.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0153-ORACLE11 - DBA roles assignments should be assigned and authorized by the IAO.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0165-ORACLE11 - DBMS symmetric keys should be protected in accordance with NSA or NIST-approved key management technology or processes.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0190-ORACLE11 - Credentials stored and used by the DBMS to access remote databases or applications should be authorized and restricted to authorized users.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO0210-ORACLE11 - Access to default accounts used to support replication should be restricted to authorized DBAs - 'sys.dba_repcatlog count = 0'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO0233-ORACLE11 - The /diag subdirectory under the directory assigned to the DIAGNOSTIC_DEST parameter must be protected from unauthorized access.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO0234-ORACLE11 - The directory assigned to the AUDIT_FILE_DEST parameter should be protected from unauthorized access - 'audit_trail value = TRUE, OS, XML or XML, EXTENDED'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO0238-ORACLE11 - The directories assigned to the LOG_ARCHIVE_DEST* parameters should be protected from unauthorized access - 'log_archive_dest parameter is configured'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO0238-ORACLE11 - The directories assigned to the LOG_ARCHIVE_DEST* parameters should be protected from unauthorized access - 'log_archive_dest_n parameter is configured'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO0238-ORACLE11 - The directories assigned to the LOG_ARCHIVE_DEST* parameters should be protected from unauthorized access - 'LOG_MODE = NOARCHIVELOG'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

DO3536-ORACLE11 - The IDLE_TIME profile parameter should be set for Oracle profiles IAW DoD policy - 'Default profile IDLE_TIME < 15 minutes'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

CONFIGURATION MANAGEMENT

DO3622-ORACLE11 - Oracle roles granted using the WITH ADMIN OPTION should not be granted to unauthorized accounts.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DO3685-ORACLE11 - The Oracle O7_DICTIONARY_ACCESSIBILITY parameter should be set to FALSE - 'O7_dictionary_accessibility = false'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
O19C-00-000100 - Oracle Database must limit the number of concurrent sessions for each system account to an organization-defined number of sessions.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

ACCESS CONTROL

O19C-00-002000 - Oracle Database must generate audit records for the DOD-selected list of auditable events, when successfully accessed, added, modified, or deleted, to the extent such information is available.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

O19C-00-005900 - The Oracle Database, or the logging or alerting mechanism the application uses, must provide a warning when allocated audit record storage volume record storage volume reaches 75 percent of maximum audit record storage capacity.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

O19C-00-006900 - The system must protect audit tools from unauthorized access, modification, or deletion.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

O19C-00-007700 - Database software, applications, and configuration files must be monitored to discover unauthorized changes.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-009700 - Oracle roles granted using the WITH ADMIN OPTION must not be granted to unauthorized accounts.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-011500 - The /diag subdirectory under the directory assigned to the DIAGNOSTIC_DEST parameter must be protected from unauthorized access.DISA Oracle Database 19c STIG v1r3 WindowsWindows

CONFIGURATION MANAGEMENT

O19C-00-011600 - Remote administration must be disabled for the Oracle connection manager.DISA Oracle Database 19c STIG v1r5 UnixUnix

CONFIGURATION MANAGEMENT

O19C-00-011600 - Remote administration must be disabled for the Oracle connection manager.DISA Oracle Database 19c STIG v1r5 WindowsWindows

CONFIGURATION MANAGEMENT

O19C-00-011800 - Database administrator (DBA) OS accounts must be granted only those host system privileges necessary for the administration of the Oracle Database.DISA Oracle Database 19c STIG v1r5 WindowsWindows

CONFIGURATION MANAGEMENT

O19C-00-012200 - Oracle Database must be protected from unauthorized access by developers on shared production/development host systems.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-012400 - Oracle Database must set the maximum number of consecutive invalid logon attempts to three.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-015300 - Oracle Database must map the authenticated identity to the user account using public key infrastructure (PKI)-based authentication.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

O19C-00-016900 - Oracle Database must implement cryptographic mechanisms to prevent unauthorized modification of organization-defined information at rest (to include, at a minimum, PII and classified information) on organization-defined information system components.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

SYSTEM AND COMMUNICATIONS PROTECTION

O19C-00-019800 - Oracle Database must, for password-based authentication, verify that when users create or update passwords, the passwords are not found on the list of commonly used, expected, or compromised passwords in IA-5 (1) (a).DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

O19C-00-019900 - Oracle Database must, for password-based authentication, require immediate selection of a new password upon account recovery.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION