Item Search

NameAudit NamePluginCategory
DG0032-ORACLE11 - Audit records should be restricted to authorized individuals - 'AUD$ table access is restricted'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0071-ORACLE11 - New passwords must be required to differ from old passwords by more than four characters - 'PASSWORD_VERIFY_FUNCTION is not set to NULL or DEFAULT'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0078-ORACLE11 - Each database user, application or process should have an individually assigned account.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0091-ORACLE11 - Custom and GOTS application source code stored in the database should be protected with encryption or encoding.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

SYSTEM AND COMMUNICATIONS PROTECTION

DG0105-ORACLE11 - DBMS application user roles should not be assigned unauthorized privileges.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0116-ORACLE11 - Database privileged role assignments should be restricted to IAO-authorized DBMS accounts.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DG0119-ORACLE11 - DBMS application users should not be granted administrative privileges to the DBMS.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DG0127-ORACLE11 - DBMS account passwords should not be set to easily guessed words or values - 'profile'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0135-ORACLE11 - Users should be alerted upon login of previous successful connections or unsuccessful attempts to access their account.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0153-ORACLE11 - DBA roles assignments should be assigned and authorized by the IAO.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO0210-ORACLE11 - Access to default accounts used to support replication should be restricted to authorized DBAs - 'sys.dba_repcatlog count = 0'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO0233-ORACLE11 - The /diag subdirectory under the directory assigned to the DIAGNOSTIC_DEST parameter must be protected from unauthorized access.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO0234-ORACLE11 - The directory assigned to the AUDIT_FILE_DEST parameter should be protected from unauthorized access - 'audit_trail value = TRUE, OS, XML or XML, EXTENDED'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO0238-ORACLE11 - The directories assigned to the LOG_ARCHIVE_DEST* parameters should be protected from unauthorized access - 'log_archive_dest_n parameter is configured'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO3536-ORACLE11 - The IDLE_TIME profile parameter should be set for Oracle profiles IAW DoD policy - 'Default profile IDLE_TIME < 15 minutes'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

CONFIGURATION MANAGEMENT

DO3546-ORACLE11 - The Oracle REMOTE_LOGIN_PASSWORDFILE parameter should be set to EXCLUSIVE or NONE - 'remote_login_passwordfile = exclusive or none'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO3609-ORACLE11 - System privileges granted using the WITH ADMIN OPTION should not be granted to unauthorized user accounts - 'No accounts granted with admin option exist'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DO3612-ORACLE11 - System Privileges should not be granted to PUBLIC - 'No system privileges granted to PUBLIC'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DO3685-ORACLE11 - The Oracle O7_DICTIONARY_ACCESSIBILITY parameter should be set to FALSE - 'O7_dictionary_accessibility = false'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO6748-ORACLE11 - Case sensitivity for passwords should be enabled - 'sec_case_sensitive_logon = true'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
O19C-00-000100 - Oracle Database must limit the number of concurrent sessions for each system account to an organization-defined number of sessions.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

ACCESS CONTROL

O19C-00-000300 - Oracle Database must automatically terminate a user session after organization-defined conditions or trigger events requiring session disconnect.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

ACCESS CONTROL

O19C-00-000300 - Oracle Database must automatically terminate a user session after organization-defined conditions or trigger events requiring session disconnect.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

ACCESS CONTROL

O19C-00-005900 - The Oracle Database, or the logging or alerting mechanism the application uses, must provide a warning when allocated audit record storage volume record storage volume reaches 75 percent of maximum audit record storage capacity.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

O19C-00-006900 - The system must protect audit tools from unauthorized access, modification, or deletion.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

O19C-00-008100 - Database software directories, including database management system (DBMS) configuration files, must be stored in dedicated directories, or DASD pools, separate from the host OS and other applications.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-008200 - Database objects must be owned by accounts authorized for ownership.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-008300 - The role(s)/group(s) used to modify database structure (including but not necessarily limited to tables, indexes, storage, etc.) and logic modules (stored procedures, functions, triggers, links to software external to the DBMS, etc.) must be restricted to authorized users.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-009000 - The Oracle WITH GRANT OPTION privilege must not be granted to nondatabase administrator (DBA) or nonapplication administrator user accounts.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-009500 - System privileges granted using the WITH ADMIN OPTION must not be granted to unauthorized user accounts.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-009600 - System Privileges must not be granted to PUBLIC.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-009700 - Oracle roles granted using the WITH ADMIN OPTION must not be granted to unauthorized accounts.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-011500 - The /diag subdirectory under the directory assigned to the DIAGNOSTIC_DEST parameter must be protected from unauthorized access.DISA Oracle Database 19c STIG v1r3 UnixUnix

CONFIGURATION MANAGEMENT

O19C-00-011500 - The /diag subdirectory under the directory assigned to the DIAGNOSTIC_DEST parameter must be protected from unauthorized access.DISA Oracle Database 19c STIG v1r3 WindowsWindows

CONFIGURATION MANAGEMENT

O19C-00-011600 - Remote administration must be disabled for the Oracle connection manager.DISA Oracle Database 19c STIG v1r5 UnixUnix

CONFIGURATION MANAGEMENT

O19C-00-011800 - Database administrator (DBA) OS accounts must be granted only those host system privileges necessary for the administration of the Oracle Database.DISA Oracle Database 19c STIG v1r3 UnixUnix

CONFIGURATION MANAGEMENT

O19C-00-011800 - Database administrator (DBA) OS accounts must be granted only those host system privileges necessary for the administration of the Oracle Database.DISA Oracle Database 19c STIG v1r3 WindowsWindows

CONFIGURATION MANAGEMENT

O19C-00-012000 - Oracle Database must provide a mechanism to automatically identify accounts designated as temporary or emergency accounts.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-012100 - Oracle Database must provide a mechanism to automatically remove or disable temporary user accounts after 72 hours.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-012100 - Oracle Database must provide a mechanism to automatically remove or disable temporary user accounts after 72 hours.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-012200 - Oracle Database must be protected from unauthorized access by developers on shared production/development host systems.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-012300 - Oracle Database must verify account lockouts persist until reset by an administrator.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-012400 - Oracle Database must set the maximum number of consecutive invalid logon attempts to three.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-013800 - Oracle Database must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

O19C-00-014600 - Procedures for establishing temporary passwords that meet DOD password requirements for new accounts must be defined, documented, and implemented.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

O19C-00-015600 - Oracle Database must uniquely identify and authenticate nonorganizational users (or processes acting on behalf of nonorganizational users).DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

O19C-00-016900 - Oracle Database must implement cryptographic mechanisms to prevent unauthorized modification of organization-defined information at rest (to include, at a minimum, PII and classified information) on organization-defined information system components.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

SYSTEM AND COMMUNICATIONS PROTECTION

O19C-00-017600 - Access to Oracle Database files must be limited to relevant processes and to authorized, administrative users.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

SYSTEM AND COMMUNICATIONS PROTECTION

O19C-00-018400 - Oracle Database must restrict error messages so only authorized personnel may view them.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

SYSTEM AND INFORMATION INTEGRITY

O19C-00-019900 - Oracle Database must, for password-based authentication, require immediate selection of a new password upon account recovery.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION