STIGQter STIGQter: STIG Summary: Oracle Database 11g Installation STIG Version: 8 Release: 20 Benchmark Date: 28 Jul 2017:

All applications that access the database should be logged in the audit trail.

DISA Rule

SV-24626r1_rule

Vulnerability Number

V-3807

Group Title

DBMS software access audit

Rule Version

DG0052-ORACLE11

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Modify auditing to ensure audit records include identification of applications used to access the DBMS.

Ensure auditing captures the name [or unique identifier] of applications accessing the DBMS at a minimum.

Develop or procure a 3rd-party solution where native DBMS logging is not employed or does not capture required information.

Check Contents

Review the DBMS audit trail to determine if the names [or unique identifiers] of applications used to connect to the database are included.

If an alternate method other than DBMS logging is authorized and implemented, review the audit trail to determine if the names [or unique identifiers] of applications used to connect to the database are included.

If application access to the DBMS is not being audited, this is a Finding.

If auditing does not capture the name [or unique identifier] of applications accessing the DBMS at a minimum, this is a Finding.

Vulnerability Number

V-3807

Documentable

False

Rule Version

DG0052-ORACLE11

Severity Override Guidance

Review the DBMS audit trail to determine if the names [or unique identifiers] of applications used to connect to the database are included.

If an alternate method other than DBMS logging is authorized and implemented, review the audit trail to determine if the names [or unique identifiers] of applications used to connect to the database are included.

If application access to the DBMS is not being audited, this is a Finding.

If auditing does not capture the name [or unique identifier] of applications accessing the DBMS at a minimum, this is a Finding.

Check Content Reference

M

Responsibility

Database Administrator

Target Key

1368

Comments