STIGQter STIGQter: STIG Summary: Oracle Database 11g Installation STIG Version: 8 Release: 20 Benchmark Date: 28 Jul 2017:

A production DBMS installation should not coexist on the same DBMS host with other, non-production DBMS installations.

DISA Rule

SV-24606r1_rule

Vulnerability Number

V-3803

Group Title

DBMS shared production/development use

Rule Version

DG0017-ORACLE11

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Recommend establishing a dedicated DBMS host for production DBMS installations (See Checks DG0109 and DG0110).

A dedicated host system in this case refers to an instance of the operating system at a minimum.

The operating system may reside on a virtual host machine where supported by the DBMS vendor.

Check Contents

Review the System Security Plan and interview the DBA and IAO to determine if the DBMS host contains production and non-production DBMS installations.

If the DBMS host contains both production and non-production DBMS installations or the production DBMS installation is being used for non-production efforts, determine if this allowance is documented in the System Security Plan and authorized by the IAO.

If not documented and authorized, this is a Finding.

NOTE: Though shared production/non-production DBMS installations was allowed under previous database STIG guidance, doing so may place it in violation of OS, Application, Network or Enclave STIG guidance. Ensure that any shared production/non-production DBMS installations meets STIG guidance requirements at all levels or mitigate any conflicts in STIG guidance with your DAA.

Vulnerability Number

V-3803

Documentable

False

Rule Version

DG0017-ORACLE11

Severity Override Guidance

Review the System Security Plan and interview the DBA and IAO to determine if the DBMS host contains production and non-production DBMS installations.

If the DBMS host contains both production and non-production DBMS installations or the production DBMS installation is being used for non-production efforts, determine if this allowance is documented in the System Security Plan and authorized by the IAO.

If not documented and authorized, this is a Finding.

NOTE: Though shared production/non-production DBMS installations was allowed under previous database STIG guidance, doing so may place it in violation of OS, Application, Network or Enclave STIG guidance. Ensure that any shared production/non-production DBMS installations meets STIG guidance requirements at all levels or mitigate any conflicts in STIG guidance with your DAA.

Check Content Reference

I

Responsibility

Information Assurance Officer

Target Key

1368

Comments