Item Search

NameAudit NamePluginCategory
1.27 O19C-00-008600CIS Oracle Database 19c STIG v1.1.0 CAT II OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-BP-021300 - Oracle instance names must not contain Oracle version numbers.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-BP-021500 - A minimum of two Oracle control files must be defined and configured to be stored on separate, archived disks (physical or virtual) or archived partitions on a RAID device.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-BP-021700 - The Oracle WITH GRANT OPTION privilege must not be granted to non-DBA or non-Application administrator user accounts.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-BP-021900 - The Oracle REMOTE_OS_AUTHENT parameter must be set to FALSE.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-BP-022100 - The Oracle SQL92_SECURITY parameter must be set to TRUE.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-BP-022300 - System privileges granted using the WITH ADMIN OPTION must not be granted to unauthorized user accounts.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-BP-023000 - Connections by mid-tier web and application systems to the Oracle DBMS from a DMZ or external network must be encrypted.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-BP-023100 - Database job/batch queues must be reviewed regularly to detect unauthorized database job submissions.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-BP-023900 - The Oracle _TRACE_FILES_PUBLIC parameter if present must be set to FALSE.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-BP-024750 - Oracle database products must be a version supported by the vendor.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

SYSTEM AND SERVICES ACQUISITION

O121-BP-025101 - The directory assigned to the AUDIT_FILE_DEST parameter must be protected from unauthorized access and must be stored in a dedicated directory or disk partition separate from software or other application files.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-BP-025600 - Network access to the DBMS must be restricted to authorized personnel.DISA Oracle Database 12c STIG v3r5 WindowsWindows

CONFIGURATION MANAGEMENT

O121-BP-025600 - Network access to the DBMS must be restricted to authorized personnel.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-BP-025800 - Changes to configuration options must be audited.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C1-004500 - DBA OS accounts must be granted only those host system privileges necessary for the administration of the DBMS.DISA Oracle Database 12c STIG v3r5 WindowsWindows

CONFIGURATION MANAGEMENT

O121-C1-011100 - Oracle software must be evaluated and patched against newly found vulnerabilities.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C1-019700 - The DBMS must employ cryptographic mechanisms preventing the unauthorized disclosure of information during transmission unless the transmitted data is otherwise protected by alternative physical measures.DISA Oracle Database 12c STIG v3r5 WindowsWindows

SYSTEM AND COMMUNICATIONS PROTECTION

O121-C2-001700 - The DBMS must support the disabling of network protocols deemed by the organization to be nonsecure.DISA Oracle Database 12c STIG v3r5 WindowsWindows

CONFIGURATION MANAGEMENT

O121-C2-002700 - The DBMS must enforce approved authorizations for logical access to the system in accordance with applicable policy.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

ACCESS CONTROL

O121-C2-003000 - The DBMS must enforce Discretionary Access Control (DAC) policy allowing users to specify and control sharing by named individuals, groups of individuals, or by both, limiting propagation of access rights and including or excluding access to the granularity of a single user.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

ACCESS CONTROL

O121-C2-003700 - The DBMS must be protected from unauthorized access by developers.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C2-004000 - Administrative privileges must be assigned to database accounts via database roles.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C2-004100 - Administrators must utilize a separate, distinct administrative account when performing administrative activities, accessing database security functions, or accessing security-relevant information.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

SYSTEM AND COMMUNICATIONS PROTECTION

O121-C2-005000 - The DBMS must set the maximum number of consecutive invalid logon attempts to three.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C2-006700 - A DBMS utilizing Discretionary Access Control (DAC) must enforce a policy that includes or excludes access to the granularity of a single user.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

ACCESS CONTROL

O121-C2-006800 - The DBMS must provide audit record generation capability for organization-defined auditable events within the database.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

O121-C2-006900 - The DBMS must allow designated organizational personnel to select which auditable events are to be audited by the database.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

O121-C2-008000 - The DBMS must include organization-defined additional, more detailed information in the audit records for audit events identified by type, location, or subject.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

O121-C2-008200 - The DBMS itself, or the logging or alerting mechanism the application utilizes, must provide a warning when allocated audit record storage volume reaches an organization-defined percentage of maximum audit record storage capacity.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

O121-C2-009400 - The system must protect audit information from unauthorized modification.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

O121-C2-009700 - The system must protect audit tools from unauthorized modification.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

O121-C2-009800 - The system must protect audit tools from unauthorized deletion.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

O121-C2-011500 - Default demonstration and sample databases, database objects, and applications must be removed.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C2-011700 - Unused database components that are integrated in the DBMS and cannot be uninstalled must be disabled.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C2-011800 - Use of external executables must be authorized.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C2-011810 - Access to external executables must be disabled or restricted.DISA Oracle Database 12c STIG v3r5 UnixUnix

CONFIGURATION MANAGEMENT

O121-C2-011900 - The DBMS must support the organizational requirements to specifically prohibit or restrict the use of unauthorized functions, ports, protocols, and/or services.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C2-012300 - Database backup procedures must be defined, documented, and implemented.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C2-012400 - Database recovery procedures must be developed, documented, implemented, and periodically tested.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C2-013800 - The DBMS must disable user accounts after 35 days of inactivity.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C2-014100 - The DBMS must support organizational requirements to enforce password complexity by the number of uppercase characters used.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

O121-C2-014200 - The DBMS must support organizational requirements to enforce password complexity by the number of lowercase characters used.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

O121-C2-014500 - The DBMS must support organizational requirements to enforce the number of characters that get changed when passwords are changed.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

O121-C2-015200 - The DBMS must enforce password maximum lifetime restrictions.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

O121-C2-016600 - The DBMS must implement required cryptographic protections using cryptographic modules complying with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance.DISA Oracle Database 12c STIG v3r5 WindowsWindows

IDENTIFICATION AND AUTHENTICATION

O121-C2-017600 - The DBMS must terminate user sessions upon user logoff or any other organization or policy-defined session termination events, such as idle time limit exceeded.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

SYSTEM AND COMMUNICATIONS PROTECTION

O121-C2-018600 - The DBMS must automatically terminate emergency accounts after an organization-defined time period for each type of account.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C2-019100 - The DBMS must protect against or limit the effects of organization-defined types of Denial of Service (DoS) attacks.DISA Oracle Database 12c STIG v3r5 UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

O121-OS-010710 - Logic modules within the database (to include packages, procedures, functions and triggers) must be monitored to discover unauthorized changes.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT