STIGQter STIGQter: STIG Summary: Oracle Database 11g Installation STIG Version: 8 Release: 20 Benchmark Date: 28 Jul 2017:

Database data encryption controls should be configured in accordance with application requirements.

DISA Rule

SV-24707r1_rule

Vulnerability Number

V-15143

Group Title

Database data encryption configuration

Rule Version

DG0106-ORACLE11

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure DBMS encryption features and functions as required by the System Security Plan.

Discrepancies between what features are and are not available should be resolved with the Information Owner, Application Developer and DBA as overseen by the IAO.

Check Contents

Review the System Security Plan and note sensitive data identified by the Information Owner as requiring encryption using DBMS features administered by the DBA.

If no sensitive data is present or encryption of sensitive data is not required by the Information Owner, this check is Not a Finding.

Review the encryption configuration against the System Security Plan specification.

If the specified encryption is not configured, this is a Finding.

Vulnerability Number

V-15143

Documentable

False

Rule Version

DG0106-ORACLE11

Severity Override Guidance

Review the System Security Plan and note sensitive data identified by the Information Owner as requiring encryption using DBMS features administered by the DBA.

If no sensitive data is present or encryption of sensitive data is not required by the Information Owner, this check is Not a Finding.

Review the encryption configuration against the System Security Plan specification.

If the specified encryption is not configured, this is a Finding.

Check Content Reference

M

Responsibility

Database Administrator

Target Key

1368

Comments