SV-270499r1064775_rule
V-270499
SRG-APP-000023-DB-000001
O19C-00-000800
CAT I
10
Integrate database management system (DBMS) security with an organization-level authentication/access mechanism providing account management for all users, groups, roles, and any other principals.
For each Oracle-managed account that is not documented and approved, either transfer it to management by the external mechanism, or document the need for it and obtain approval, as appropriate.
Utilize an Oracle feature/product, an OS feature, a third-party product, or custom code to automate as much account maintenance functionality as possible.
If all user accounts are authenticated by the OS or an enterprise-level authentication/access mechanism, and not by Oracle, this is not a finding.
If an Oracle feature/product, an OS feature, a third-party product, or custom code is used to automate account management, this is not a finding.
If there are any accounts managed by the Oracle Database, review the system documentation for justification and approval of these accounts.
If any Oracle-managed accounts exist that are not documented and approved, this is a finding.
V-270499
False
O19C-00-000800
If all user accounts are authenticated by the OS or an enterprise-level authentication/access mechanism, and not by Oracle, this is not a finding.
If an Oracle feature/product, an OS feature, a third-party product, or custom code is used to automate account management, this is not a finding.
If there are any accounts managed by the Oracle Database, review the system documentation for justification and approval of these accounts.
If any Oracle-managed accounts exist that are not documented and approved, this is a finding.
M
5672