| 1.72 O19C-00-015200 | CIS Oracle Database 19c STIG v1.1.0 CAT I Windows | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.72 O19C-00-015200 | CIS Oracle Database 19c STIG v1.1.0 CAT I Unix | Unix | IDENTIFICATION AND AUTHENTICATION |
| 2.3.3 Ensure 'MLE_PROG_LANGUAGES' Is Set To 'OFF' | CIS Oracle Database 23ai v1.1.0 L1 RDBMS | OracleDB | CONFIGURATION MANAGEMENT |
| 2.3.3 Ensure 'MLE_PROG_LANGUAGES' Is Set To 'OFF' | CIS Oracle Database 26ai v1.0.0 L1 RDBMS | OracleDB | CONFIGURATION MANAGEMENT |
| 2.3.3 Ensure 'MLE_PROG_LANGUAGES' Is Set To 'OFF' | CIS Oracle Database 26ai v1.0.0 L1 RDBMS On Windows Server Host OS OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O19C-00-008600 - Oracle instance names must not contain Oracle version numbers. | DISA Oracle Database 19c STIG v1r3 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O19C-00-008700 - Fixed user and PUBLIC Database links must be authorized for use. | DISA Oracle Database 19c STIG v1r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O19C-00-008700 - Fixed user and PUBLIC Database links must be authorized for use. | DISA Oracle Database 19c STIG v1r3 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O19C-00-013400 - Access to external executables must be disabled or restricted. | DISA Oracle Database 19c STIG v1r3 Windows | Windows | CONFIGURATION MANAGEMENT |
| O19C-00-013400 - Access to external executables must be disabled or restricted. | DISA Oracle Database 19c STIG v1r3 Unix | Unix | CONFIGURATION MANAGEMENT |
| O19C-00-013400 - Access to external executables must be disabled or restricted. | DISA Oracle Database 19c STIG v1r5 Unix | Unix | CONFIGURATION MANAGEMENT |
| O19C-00-013400 - Access to external executables must be disabled or restricted. | DISA Oracle Database 19c STIG v1r5 Windows | Windows | CONFIGURATION MANAGEMENT |
| O19C-00-015200 - Oracle Database, when using public key infrastructure (PKI)-based authentication, must enforce authorized access to the corresponding private key. | DISA Oracle Database 19c STIG v1r5 Unix | Unix | IDENTIFICATION AND AUTHENTICATION |
| O19C-00-015200 - Oracle Database, when using public key infrastructure (PKI)-based authentication, must enforce authorized access to the corresponding private key. | DISA Oracle Database 19c STIG v1r3 Unix | Unix | IDENTIFICATION AND AUTHENTICATION |
| O19C-00-015200 - Oracle Database, when using public key infrastructure (PKI)-based authentication, must enforce authorized access to the corresponding private key. | DISA Oracle Database 19c STIG v1r5 Windows | Windows | IDENTIFICATION AND AUTHENTICATION |
| O19C-00-015200 - Oracle Database, when using public key infrastructure (PKI)-based authentication, must enforce authorized access to the corresponding private key. | DISA Oracle Database 19c STIG v1r3 Windows | Windows | IDENTIFICATION AND AUTHENTICATION |
| O19C-00-016100 - Oracle Database must separate user functionality (including user interface services) from database management functionality. | DISA Oracle Database 19c STIG v1r5 OracleDB | OracleDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| O121-BP-021200 - Access to default accounts used to support replication must be restricted to authorized DBAs. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-021400 - Fixed user and public database links must be authorized for use. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-022500 - Oracle roles granted using the WITH ADMIN OPTION must not be granted to unauthorized accounts. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-023700 - Application owner accounts must have a dedicated application tablespace. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-024100 - DBMS production application and data directories must be protected from developers on shared production/development DBMS host systems. | DISA Oracle Database 12c STIG v3r5 Unix | Unix | CONFIGURATION MANAGEMENT |
| O121-BP-024200 - Use of the DBMS installation account must be logged. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-025400 - Access to DBMS software files and directories must not be granted to unauthorized users. | DISA Oracle Database 12c STIG v3r5 Unix | Unix | CONFIGURATION MANAGEMENT |
| O121-BP-025400 - Access to DBMS software files and directories must not be granted to unauthorized users. | DISA Oracle Database 12c STIG v3r5 Windows | Windows | CONFIGURATION MANAGEMENT |
| O121-BP-026300 - Remote database or other external access must use fully-qualified names. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-026500 - Remote administration must be disabled for the Oracle connection manager. | DISA Oracle Database 12c STIG v3r5 Windows | Windows | CONFIGURATION MANAGEMENT |
| O121-C1-015000 - DBMS default accounts must be assigned custom passwords. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-C2-004400 - OS accounts utilized to run external procedures called by the DBMS must have limited privileges. | DISA Oracle Database 12c STIG v3r5 Windows | Windows | CONFIGURATION MANAGEMENT |
| O121-C2-004900 - The DBMS must verify account lockouts persist until reset by an administrator. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-C2-006600 - Databases utilizing Discretionary Access Control (DAC) must enforce a policy that limits propagation of access rights. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | ACCESS CONTROL |
| O121-C2-007000 - The DBMS must generate audit records for the DoD-selected list of auditable events, to the extent such information is available. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | AUDIT AND ACCOUNTABILITY |
| O121-C2-007900 - The DBMS must produce audit records containing sufficient information to establish the identity of any user/subject or process associated with the event. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | AUDIT AND ACCOUNTABILITY |
| O121-C2-009300 - The system must protect audit information from any type of unauthorized access. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | AUDIT AND ACCOUNTABILITY |
| O121-C2-013300 - The DBMS must ensure users are authenticated with an individual authenticator prior to using a shared authenticator. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | IDENTIFICATION AND AUTHENTICATION |
| O121-C2-013900 - The DBMS must support organizational requirements to enforce minimum password length. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | IDENTIFICATION AND AUTHENTICATION |
| O121-C2-014000 - The DBMS must support organizational requirements to prohibit password reuse for the organization-defined number of generations. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | IDENTIFICATION AND AUTHENTICATION |
| O121-C2-014600 - The DBMS must support organizational requirements to enforce password encryption for storage. | DISA Oracle Database 12c STIG v3r5 Windows | Windows | IDENTIFICATION AND AUTHENTICATION |
| O121-C2-016500 - The DBMS must terminate the network connection associated with a communications session at the end of the session or 15 minutes of inactivity. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | ACCESS CONTROL |
| O121-C2-016600 - The DBMS must implement required cryptographic protections using cryptographic modules complying with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance. | DISA Oracle Database 12c STIG v3r5 Unix | Unix | IDENTIFICATION AND AUTHENTICATION |
| O121-C2-018500 - The DBMS must isolate security functions from nonsecurity functions by means of separate security domains. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| O121-C2-019100 - The DBMS must protect against or limit the effects of organization-defined types of Denial of Service (DoS) attacks. | DISA Oracle Database 12c STIG v3r5 Windows | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| O121-C2-019600 - The system must verify there have not been unauthorized changes to the DBMS software and information. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | SYSTEM AND INFORMATION INTEGRITY |
| O121-N1-015601 - Applications must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-N1-015602 - When using command-line tools such as Oracle SQL*Plus, which can accept a plain-text password, users must use an alternative logon method that does not expose the password. | DISA Oracle Database 12c STIG v3r5 Windows | Windows | CONFIGURATION MANAGEMENT |
| O121-N2-008601 - The DBMS must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-OS-011200 - The OS must limit privileges to change the DBMS software resident within software libraries (including privileged programs). | DISA Oracle Database 12c STIG v3r5 Unix | Unix | CONFIGURATION MANAGEMENT |
| O121-OS-011200 - The OS must limit privileges to change the DBMS software resident within software libraries (including privileged programs). | DISA Oracle Database 12c STIG v3r5 Windows | Windows | CONFIGURATION MANAGEMENT |
| O121-P2-012800 - The DBMS must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | IDENTIFICATION AND AUTHENTICATION |
| O121-P2-017300 - The DBMS must separate user functionality (including user interface services) from database management functionality. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | SYSTEM AND COMMUNICATIONS PROTECTION |