STIGQter STIGQter: STIG Summary: Oracle Database 12c Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Apr 2021:

The DBMS must be protected from unauthorized access by developers.

DISA Rule

SV-237706r667150_rule

Vulnerability Number

V-237706

Group Title

SRG-APP-000133-DB-000362

Rule Version

O121-C2-003700

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Restrict developer privileges to production objects to only objects and data where those privileges are required and authorized. Document the approval and risk acceptance.

Consider using separate accounts for a person's developer duties and production duties. At a minimum, use separate roles for developer privileges and production privileges.

If developers need the ability to create and maintain tables (or other database objects) as part of their development activities, provide dedicated tablespaces, and revoke any rights that allowed them to use production tablespaces for this purpose.

Check Contents

Check the production system to ensure no developer accounts have rights to modify the production database structure or alter production data.

If developer accounts with these rights exist, ask for documentation that shows these accounts have formal approval and risk acceptance. If this documentation does not exist, this is a finding.

If developer accounts exist with the right to create and maintain tables (or other database objects) in production tablespaces, this is a finding.

Vulnerability Number

V-237706

Documentable

False

Rule Version

O121-C2-003700

Severity Override Guidance

Check the production system to ensure no developer accounts have rights to modify the production database structure or alter production data.

If developer accounts with these rights exist, ask for documentation that shows these accounts have formal approval and risk acceptance. If this documentation does not exist, this is a finding.

If developer accounts exist with the right to create and maintain tables (or other database objects) in production tablespaces, this is a finding.

Check Content Reference

M

Target Key

4059

Comments