| DO0220-ORACLE11 - Oracle instance names should not contain Oracle version numbers. | DISA STIG Oracle 11 Instance v9r1 Database | OracleDB | |
| O121-BP-021600 - A minimum of two Oracle redo log groups/files must be defined and configured to be stored on separate, archived physical disks or archived directories on a RAID device. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-022000 - The Oracle REMOTE_OS_ROLES parameter must be set to FALSE. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-022200 - The Oracle password file ownership and permissions should be limited and the REMOTE_LOGIN_PASSWORDFILE parameter must be set to EXCLUSIVE or NONE. | DISA Oracle Database 12c STIG v3r5 Windows | Windows | CONFIGURATION MANAGEMENT |
| O121-BP-022200 - The Oracle password file ownership and permissions should be limited and the REMOTE_LOGIN_PASSWORDFILE parameter must be set to EXCLUSIVE or NONE. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-022400 - System Privileges must not be granted to PUBLIC. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-022600 - Object permissions granted to PUBLIC must be restricted. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-022800 - Application role permissions must not be assigned to the Oracle PUBLIC role. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-022900 - Oracle application administration roles must be disabled if not required and authorized. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-023300 - Sensitive information from production database exports must be modified before import to a development database. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-023600 - Only authorized system accounts must have the SYSTEM tablespace specified as the default tablespace. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-023800 - The directories assigned to the LOG_ARCHIVE_DEST* parameters must be protected from unauthorized access. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-024100 - DBMS production application and data directories must be protected from developers on shared production/development DBMS host systems. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-025500 - Replication accounts must not be granted DBA privileges. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-025600 - Network access to the DBMS must be restricted to authorized personnel. | DISA Oracle Database 12c STIG v3r5 Unix | Unix | CONFIGURATION MANAGEMENT |
| O121-BP-026200 - Changes to DBMS security labels must be audited. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-026400 - The /diag subdirectory under the directory assigned to the DIAGNOSTIC_DEST parameter must be protected from unauthorized access. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-BP-026500 - Remote administration must be disabled for the Oracle connection manager. | DISA Oracle Database 12c STIG v3r5 Unix | Unix | CONFIGURATION MANAGEMENT |
| O121-C1-004500 - DBA OS accounts must be granted only those host system privileges necessary for the administration of the DBMS. | DISA Oracle Database 12c STIG v3r5 Unix | Unix | CONFIGURATION MANAGEMENT |
| O121-C1-015400 - The DBMS, when using PKI-based authentication, must enforce authorized access to the corresponding private key. | DISA Oracle Database 12c STIG v3r5 Unix | Unix | IDENTIFICATION AND AUTHENTICATION |
| O121-C1-015400 - The DBMS, when using PKI-based authentication, must enforce authorized access to the corresponding private key. | DISA Oracle Database 12c STIG v3r5 Windows | Windows | IDENTIFICATION AND AUTHENTICATION |
| O121-C1-019700 - The DBMS must employ cryptographic mechanisms preventing the unauthorized disclosure of information during transmission unless the transmitted data is otherwise protected by alternative physical measures. | DISA Oracle Database 12c STIG v3r5 Unix | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| O121-C2-000100 - The DBMS must limit the number of concurrent sessions for each system account to an organization-defined number of sessions. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | ACCESS CONTROL |
| O121-C2-001700 - The DBMS must support the disabling of network protocols deemed by the organization to be nonsecure. | DISA Oracle Database 12c STIG v3r5 Unix | Unix | CONFIGURATION MANAGEMENT |
| O121-C2-001800 - The system must employ automated mechanisms for supporting Oracle user account management. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | ACCESS CONTROL |
| O121-C2-001900 - The DBMS must provide a mechanism to automatically identify accounts designated as temporary or emergency accounts. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-C2-002000 - The DBMS must provide a mechanism to automatically remove or disable temporary user accounts after 72 hours. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-C2-003600 - A single database connection configuration file must not be used to configure all database clients. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-C2-003800 - The DBMS must be protected from unauthorized access by developers on shared production/development host systems. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-C2-003900 - The DBMS must restrict access to system tables and other configuration information or metadata to DBAs or other authorized users. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| O121-C2-004400 - OS accounts utilized to run external procedures called by the DBMS must have limited privileges. | DISA Oracle Database 12c STIG v3r5 Unix | Unix | CONFIGURATION MANAGEMENT |
| O121-C2-008300 - The system must provide a real-time alert when organization-defined audit failure events occur. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | AUDIT AND ACCOUNTABILITY |
| O121-C2-009500 - The system must protect audit information from unauthorized deletion. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | AUDIT AND ACCOUNTABILITY |
| O121-C2-011000 - Database objects must be owned by accounts authorized for ownership. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-C2-011810 - Access to external executables must be disabled or restricted. | DISA Oracle Database 12c STIG v3r5 Windows | Windows | CONFIGURATION MANAGEMENT |
| O121-C2-012500 - DBMS backup and restoration files must be protected from unauthorized access. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| O121-C2-014300 - The DBMS must support organizational requirements to enforce password complexity by the number of numeric characters used. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | IDENTIFICATION AND AUTHENTICATION |
| O121-C2-015100 - DBMS passwords must not be stored in compiled, encoded, or encrypted batch jobs or compiled, encoded, or encrypted application source code. | DISA Oracle Database 12c STIG v3r5 Windows | Windows | CONFIGURATION MANAGEMENT |
| O121-C2-015100 - DBMS passwords must not be stored in compiled, encoded, or encrypted batch jobs or compiled, encoded, or encrypted application source code. | DISA Oracle Database 12c STIG v3r5 Unix | Unix | CONFIGURATION MANAGEMENT |
| O121-C2-015300 - The DBMS, when utilizing PKI-based authentication, must validate certificates by constructing a certification path with status information to an accepted trust anchor. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | IDENTIFICATION AND AUTHENTICATION |
| O121-C2-015501 - Oracle Database must map the PKI-authenticated identity to an associated user account - services, applications, etc. that connect to the DBMS independently of individual users, must use valid, current DoD approved PKI certificates for authentication to the DBMS. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | IDENTIFICATION AND AUTHENTICATION |
| O121-C2-016600 - The DBMS must implement required cryptographic protections using cryptographic modules complying with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | IDENTIFICATION AND AUTHENTICATION |
| O121-C2-016700 - Database data files containing sensitive information must be encrypted. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-C2-018200 - The DBMS must preserve any organization-defined system state information in the event of a system failure. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| O121-C2-018300 - The DBMS must take needed steps to protect data at rest and ensure confidentiality and integrity of application data. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| O121-C2-019900 - The DBMS must only generate error messages that provide information necessary for corrective actions without revealing organization-defined sensitive or potentially harmful information in error logs and administrative messages that could be exploited. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | SYSTEM AND INFORMATION INTEGRITY |
| O121-OS-004600 - Use of the DBMS software installation account must be restricted. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-OS-010700 - Database software, applications, and configuration files must be monitored to discover unauthorized changes. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O121-P2-008100 - Oracle Database must off-load audit data to a separate log management facility; this must be continuous and in near-real-time for systems with a network connection to the storage facility, and weekly or more often for stand-alone systems. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | AUDIT AND ACCOUNTABILITY |
| O121-P2-010800 - The DBMS software installation account must be restricted to authorized users. | DISA Oracle Database 12c STIG v3r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |