Item Search

NameAudit NamePluginCategory
1.40 O19C-00-010400CIS Oracle Database 19c STIG v1.1.0 CAT II OracleDBOracleDB

CONFIGURATION MANAGEMENT

1.69 O19C-00-014700CIS Oracle Database 19c STIG v1.1.0 CAT II OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

2.04 tkprof - 'Remove from system'CIS v1.1.0 Oracle 11g OS L1Unix
4.43 listener.ora - 'extproc_dlls = ONLY'CIS v1.1.0 Oracle 11g OS Windows Level 1Windows

CONFIGURATION MANAGEMENT

DG0040-ORACLE11 - The DBMS software installation account should be restricted to authorized users - '$ORACLE_BASE owner, group and permissions are configured'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONFIGURATION MANAGEMENT

DG0040-ORACLE11 - The DBMS software installation account should be restricted to authorized users - '$ORACLE_HOME owner, group and permissions are configured'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONFIGURATION MANAGEMENT

DG0040-ORACLE11 - The DBMS software installation account should be restricted to authorized users - 'Oracle base directory file permissions are correct'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0040-ORACLE11 - The DBMS software installation account should be restricted to authorized users - 'Oracle home directory file permissions are correct'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0040-ORACLE11 - The DBMS software installation account should be restricted to authorized users - 'Oracle install account is disabled'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

ACCESS CONTROL

DG0070-ORACLE11 - Unauthorized user accounts should not exist.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DG0073-ORACLE11 - Database accounts should not specify account lock times less than the site-approved minimum - 'Account lockout is < 3'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0100-ORACLE11 - Replication accounts should not be granted DBA privileges.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0117-ORACLE11 - Administrative privileges should be assigned to database accounts via database roles.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DISA_STIG_McAfee_VirusScan_8.8_Managed_Client_v6r1.audit from DISA McAfee VirusScan 8.8 Managed Client Security Technical implementation Guide v6r1 STIGDISA McAfee VirusScan 8.8 Managed Client STIG v6r1Windows
DISA_STIG_VMware_vSphere_8.0_vCenter_Appliance_ESX_Agent_Manager_EAM_v2r2.audit from DISA VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v2r2DISA VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v2r2Unix
DISA_STIG_VMware_vSphere_8.0_vCenter_Appliance_Secure_Token_Service_STS_v2r2.audit from DISA VMware vSphere 8.0 vCenter Appliance Secure Token Service STS STIG v2r2DISA VMware vSphere 8.0 vCenter Appliance Secure Token Service STS STIG v2r2Unix
DO0210-ORACLE11 - Access to default accounts used to support replication should be restricted to authorized DBAs - 'No replication objects exist'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO0238-ORACLE11 - The directories assigned to the LOG_ARCHIVE_DEST* parameters should be protected from unauthorized access - 'log_archive_duplex_dest parameter is not configured'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO0350-ORACLE11 - Oracle system privileges should not be directly assigned to unauthorized accounts.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DO3447-ORACLE11 - The Oracle OS_AUTHENT_PREFIX parameter should be changed from the default value of OPS$ - 'os_authent_prefix = OPS$'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO3536-ORACLE11 - The IDLE_TIME profile parameter should be set for Oracle profiles IAW DoD policy - 'Non-default profile IDLE_TIME < 15 minutes'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

CONFIGURATION MANAGEMENT

DO3610-ORACLE11 - Required object auditing should be configured - 'all_def_audit_opts count <> 0'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

AUDIT AND ACCOUNTABILITY

DO3610-ORACLE11 - Required object auditing should be configured - 'Auditing for update and delete is enabled'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

AUDIT AND ACCOUNTABILITY

O19C-00-000200 - Oracle Database must protect against or limit the effects of organization-defined types of denial-of-service (DoS) attacks.DISA Oracle Database 19c STIG v1r5 UnixUnix

ACCESS CONTROL

O19C-00-002000 - Oracle Database must generate audit records for the DOD-selected list of auditable events, when successfully accessed, added, modified, or deleted, to the extent such information is available.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

O19C-00-006000 - Oracle Database must provide an immediate real-time alert to appropriate support staff of all audit log failures.DISA Oracle Database 19c STIG v1r3 UnixUnix

AUDIT AND ACCOUNTABILITY

O19C-00-007900 - The OS must limit privileges to change the database management system (DBMS) software resident within software libraries (including privileged programs).DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-009000 - The Oracle WITH GRANT OPTION privilege must be limited when granted to nondatabase administrator (DBA) or nonapplication administrator user accounts.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-009600 - System Privileges must not be granted to PUBLIC.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-010100 - Oracle application administration roles must be disabled if not required and authorized.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-010600 - Oracle Database production application and data directories must be protected from developers on shared production/development database management system (DBMS) host systems.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-010600 - Oracle Database production application and data directories must be protected from developers on shared production/development database management system (DBMS) host systems.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-011500 - The /diag subdirectory under the directory assigned to the DIAGNOSTIC_DEST parameter must be protected from unauthorized access.DISA Oracle Database 19c STIG v1r5 WindowsWindows

CONFIGURATION MANAGEMENT

O19C-00-011500 - The /diag subdirectory under the directory assigned to the DIAGNOSTIC_DEST parameter must be protected from unauthorized access.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-012000 - Oracle Database must provide a mechanism to automatically identify accounts designated as temporary or emergency accounts.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-012400 - Oracle Database must set the maximum number of consecutive invalid logon attempts to three.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-013300 - Use of external executables must be authorized.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-013500 - Oracle Database must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL) and vulnerability assessments.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-013500 - Oracle Database must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL) and vulnerability assessments.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-013700 - Oracle Database must ensure users are authenticated with an individual authenticator prior to using a shared authenticator.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

O19C-00-013700 - Oracle Database must ensure users are authenticated with an individual authenticator prior to using a shared authenticator.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

O19C-00-013800 - Oracle Database must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

O19C-00-017400 - Oracle Database contents must be protected from unauthorized and unintended information transfer by enforcement of a data-transfer policy.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

SYSTEM AND COMMUNICATIONS PROTECTION

O19C-00-017700 - Oracle Database must employ cryptographic mechanisms preventing the unauthorized disclosure of information during transmission unless the transmitted data is otherwise protected by alternative physical measures.DISA Oracle Database 19c STIG v1r5 UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

O19C-00-018400 - Oracle Database must restrict error messages so only authorized personnel may view them.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

SYSTEM AND INFORMATION INTEGRITY

OH12-1X-000220 - OHS must have all applicable patches (i.e., CPUs) applied/documented (OEM).DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

CONFIGURATION MANAGEMENT

VCENTER-000023 - A least-privileges assignment must be used for the vCenter Server database user.DISA STIG VMWare ESXi vCenter 5 STIG v2r1VMware

CONFIGURATION MANAGEMENT

WBLC-10-000271 - Oracle WebLogic must be managed through a centralized enterprise tool.Oracle WebLogic Server 12c Linux v2r2Unix

CONFIGURATION MANAGEMENT

WBLC-10-000271 - Oracle WebLogic must be managed through a centralized enterprise tool.Oracle WebLogic Server 12c Linux v2r2 MiddlewareUnix

CONFIGURATION MANAGEMENT

WBLC-10-000271 - Oracle WebLogic must be managed through a centralized enterprise tool.Oracle WebLogic Server 12c Windows v2r2Windows

CONFIGURATION MANAGEMENT