STIGQter STIGQter: STIG Summary: Oracle Database 11g Installation STIG Version: 8 Release: 20 Benchmark Date: 28 Jul 2017:

The IAM should review changes to DBA role assignments.

DISA Rule

SV-24742r1_rule

Vulnerability Number

V-15127

Group Title

IAM review of change in DBA assignments

Rule Version

DG0118-ORACLE11

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Develop, document and implement procedures to monitor changes to DBA role assignments.

Develop, document and implement procedures to notify the IAM of changes to DBA role assignments.

Include in the procedures methods that provide evidence of monitoring and notification.

Check Contents

Review policy and procedures documented or noted in the System Security Plan as well as evidence of implementation for monitoring changes to DBA role assignments and procedures for notifying the IAM of the changes for review.

If policy, procedures or implementation evidence do not exist, this is a Finding.

Vulnerability Number

V-15127

Documentable

False

Rule Version

DG0118-ORACLE11

Severity Override Guidance

Review policy and procedures documented or noted in the System Security Plan as well as evidence of implementation for monitoring changes to DBA role assignments and procedures for notifying the IAM of the changes for review.

If policy, procedures or implementation evidence do not exist, this is a Finding.

Check Content Reference

I

Responsibility

Information Assurance Manager

Target Key

1368

Comments