Audits
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
Tenable OT Security Families
Tenable Cloud Security Families
Tenable Self-Hosted Container Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Release Notes
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
Tenable OT Security Families
Tenable Cloud Security Families
Tenable Self-Hosted Container Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Release Notes
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Audits
Item Search
Audits
Item Search
Filters (1)
Description
Filename
Plugin
References
Control ID
Relevance
Description
Plugin
Filename
References (Active)
Search by References
Clear All
‹‹ Previous
Previous
Page 4 of 200
• 10000 Total
Next
Next ››
Name
Audit Name
Plugin
Category
DG0003-ORACLE11 - The latest security patches should be installed.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0003-ORACLE11 - The latest security patches should be installed.
DISA STIG Oracle 11 Installation v9r1 Windows
Windows
DG0007-ORACLE11 - The database should be secured in accordance with DoD, vendor and/or commercially accepted practices where applicable.
DISA STIG Oracle 11 Installation v9r1 Windows
Windows
DG0007-ORACLE11 - The database should be secured in accordance with DoD, vendor and/or commercially accepted practices where applicable.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0013-ORACLE11 - Database backup procedures should be defined, documented and implemented.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0013-ORACLE11 - Database backup procedures should be defined, documented and implemented.
DISA STIG Oracle 11 Installation v9r1 Windows
Windows
DG0020-ORACLE11 - Backup and recovery procedures should be developed, documented, implemented and periodically tested.
DISA STIG Oracle 11 Installation v9r1 Windows
Windows
DG0021-ORACLE11 - A baseline of database application software should be documented and maintained.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0030-ORACLE11 - Audit trail data should be retained for one year.
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DG0051-ORACLE11 - Database job/batch queues should be reviewed regularly to detect unauthorized database job submissions - 'No unknown jobs exist in the dba_scheduler_jobs queue'
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DG0052-ORACLE11 - All applications that access the database should be logged in the audit trail.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0064-ORACLE11 - DBMS backup and restoration files should be protected from unauthorized access.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0068-ORACLE11 - DBMS tools or applications that echo or require a password entry in clear text should be protected from password display.
DISA STIG Oracle 11 Installation v9r1 Windows
Windows
DG0069-ORACLE11 - Procedures and restrictions for import of production data to development databases should be documented, implemented and followed.
DISA STIG Oracle 11 Installation v9r1 Windows
Windows
DG0083-ORACLE11 - Automated notification of suspicious activity detected in the audit trail should be implemented.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0083-ORACLE11 - Automated notification of suspicious activity detected in the audit trail should be implemented.
DISA STIG Oracle 11 Installation v9r1 Windows
Windows
DG0090-ORACLE11 - Sensitive information stored in the database should be protected by encryption.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0095-ORACLE11 - Audit trail data should be reviewed daily or more frequently.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0097-ORACLE11 - Plans and procedures for testing DBMS installations, upgrades and patches should be defined and followed prior to production implementation.
DISA STIG Oracle 11 Installation v9r1 Windows
Windows
DG0106-ORACLE11 - Database data encryption controls should be configured in accordance with application requirements.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0107-ORACLE11 - Sensitive data is stored in the database and should be identified in the System Security Plan and AIS Functional Architecture documentation.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0107-ORACLE11 - Sensitive data is stored in the database and should be identified in the System Security Plan and AIS Functional Architecture documentation.
DISA STIG Oracle 11 Installation v9r1 Windows
Windows
DG0122-ORACLE11 - Access to sensitive data should be restricted to authorized users identified by the Information Owner - 'controlfile'
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DG0122-ORACLE11 - Access to sensitive data should be restricted to authorized users identified by the Information Owner - 'spfile'
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DG0138-ORACLE11 - Access grants to sensitive data should be restricted to authorized user roles.
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DG0140-ORACLE11 - Access to DBMS security data should be audited.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0146-ORACLE11 - Audit records should include the reason for blacklisting or disabling DBMS connections or accounts.
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DG0158-ORACLE11 - DBMS remote administration should be audited.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0161-ORACLE11 - An automated tool that monitors audit data and immediately reports suspicious activity should be employed for the DBMS.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0165-ORACLE11 - DBMS symmetric keys should be protected in accordance with NSA or NIST-approved key management technology or processes.
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DG0171-ORACLE11 - The DBMS should not have a connection defined to access or be accessed by a DBMS at a different classification level.
DISA STIG Oracle 11 Installation v9r1 Windows
Windows
DG0172-ORACLE11 - Changes to DBMS security labels should be audited.
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DG0176-ORACLE11 - The DBMS audit logs should be included in backup operations.
DISA STIG Oracle 11 Installation v9r1 Windows
Windows
DG0190-ORACLE11 - Credentials stored and used by the DBMS to access remote databases or applications should be authorized and restricted to authorized users.
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DG0198-ORACLE11 - Remote administration of the DBMS should be restricted to known, dedicated and encrypted network addresses and ports.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG7001-ORACLE11 - The directory assigned to the AUDIT_FILE_DEST parameter must be protected from unauthorized access and must be stored in a dedicated directory or disk partition separate from software or other application files.
DISA STIG Oracle 11 Installation v9r1 Windows
Windows
DO0220-ORACLE11 - Oracle instance names should not contain Oracle version numbers.
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DO0231-ORACLE11 - Application owner accounts should have a dedicated application tablespace.
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DO0234-ORACLE11 - The directory assigned to the AUDIT_FILE_DEST parameter should be protected from unauthorized access - 'audit_file_dest parameter is configured'
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DO0238-ORACLE11 - The directories assigned to the LOG_ARCHIVE_DEST* parameters should be protected from unauthorized access - 'log_archive_dest parameter is configured'
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DO0250-ORACLE11 - Fixed user and public database links should be authorized for use - 'sys.dba_repcatlog count = 0'
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DO3440-ORACLE11 - The DBA role should not be granted to unauthorized user accounts - 'No unauthorized DBA accounts exist'
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DO3451-ORACLE11 - The Oracle WITH GRANT OPTION privilege should not be granted to non-DBA or non-Application administrator user accounts - 'No accounts with grant option exist'
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DO3546-ORACLE11 - The Oracle REMOTE_LOGIN_PASSWORDFILE parameter should be set to EXCLUSIVE or NONE - 'remote_login_passwordfile = exclusive or none'
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DO6748-ORACLE11 - Case sensitivity for passwords should be enabled - 'sec_case_sensitive_logon = true'
DISA STIG Oracle 11 Instance v9r1 Database
OracleDB
DO6752-ORACLE11 - The Oracle SEC_PROTOCOL_ERROR_TRACE_ACTION parameter should not be set to NONE.
DISA STIG Oracle 11 Installation v9r1 Database
OracleDB
WA000-WWA050 A22 - All interactive programs must be placed in a designated directory with appropriate permissions - printenv
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
WA000-WWA060 A22 - The HTTP request message body size must be limited.
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
WA000-WWA062 A22 - The HTTP request header fields must be limited.
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
WA000-WWA066 A22 - The HTTP request line must be limited.
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
‹‹ Previous
Previous
Page 4 of 200
• 10000 Total
Next
Next ››