STIGQter STIGQter: STIG Summary: Oracle Database 19c Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 01 Apr 2026:

Oracle Database must associate organization-defined types of security labels having organization-defined security label values with information in storage.

DISA Rule

SV-270498r1167732_rule

Vulnerability Number

V-270498

Group Title

SRG-APP-000311-DB-000308

Rule Version

O19C-00-000500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Define the policy for security labels defined for the data.

Document the security label requirements and configure database security labels in accordance with the policy.

To provide reliable security labeling of information in storage, enable DBMS features; deploy third-party software; or add custom data structures, data elements, and application code.

Oracle recommends Oracle Label Security.

For additional information on Oracle Label Security:
https://docs.oracle.com/en/database/oracle/oracle-database/19/olsag/label-security-administrators-guide.pdf.

Check Contents

If no data has been identified as being sensitive or classified in the system documentation, this is not a finding.

If security labeling is not required, this is not a finding.

If security labeling requirements have been specified, but the security labeling is not implemented or does not reliably maintain labels on information in storage, this is a finding.

Vulnerability Number

V-270498

Documentable

False

Rule Version

O19C-00-000500

Severity Override Guidance

If no data has been identified as being sensitive or classified in the system documentation, this is not a finding.

If security labeling is not required, this is not a finding.

If security labeling requirements have been specified, but the security labeling is not implemented or does not reliably maintain labels on information in storage, this is a finding.

Check Content Reference

M

Target Key

5672