STIGQter STIGQter: STIG Summary: Oracle Database 11g Installation STIG Version: 8 Release: 20 Benchmark Date: 28 Jul 2017:

Use of the DBMS software installation account should be restricted to DBMS software installation, upgrade and maintenance actions.

DISA Rule

SV-24379r1_rule

Vulnerability Number

V-15111

Group Title

DBMS software installation account use

Rule Version

DG0042-ORACLE11

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Develop, document, implement procedures, and train authorized users to restrict usage of the DBMS software installation account for DBMS software installation, upgrade and maintenance only where applicable.

For Windows systems, reapplication of the fix for Check DG0019 may be necessary to reestablish correct file/directory ownership.

Check Contents

Review the DBMS account usage log for use of the Oracle DBMS software installation account.

Interview personnel authorized to access the DBMS software installation account to ask how the account is used.

If any usage of the account is to support daily operations or general DBA responsibilities, this is a Finding.

NOTE: On Windows systems, the Oracle DBMS software is installed using an account with administrator privileges. Ownership should be reassigned to a dedicated OS account used to operate the DBMS software. Except where a change in ownership is made to files/directories during a software update, any check results are not a Finding.

Vulnerability Number

V-15111

Documentable

False

Rule Version

DG0042-ORACLE11

Severity Override Guidance

Review the DBMS account usage log for use of the Oracle DBMS software installation account.

Interview personnel authorized to access the DBMS software installation account to ask how the account is used.

If any usage of the account is to support daily operations or general DBA responsibilities, this is a Finding.

NOTE: On Windows systems, the Oracle DBMS software is installed using an account with administrator privileges. Ownership should be reassigned to a dedicated OS account used to operate the DBMS software. Except where a change in ownership is made to files/directories during a software update, any check results are not a Finding.

Check Content Reference

I

Responsibility

Information Assurance Officer

Target Key

1368

Comments