STIGQter STIGQter: STIG Summary: Oracle Database 19c Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 01 Apr 2026:

Oracle Database must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.

DISA Rule

SV-270499r1064775_rule

Vulnerability Number

V-270499

Group Title

SRG-APP-000023-DB-000001

Rule Version

O19C-00-000800

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Integrate database management system (DBMS) security with an organization-level authentication/access mechanism providing account management for all users, groups, roles, and any other principals.

For each Oracle-managed account that is not documented and approved, either transfer it to management by the external mechanism, or document the need for it and obtain approval, as appropriate.

Utilize an Oracle feature/product, an OS feature, a third-party product, or custom code to automate as much account maintenance functionality as possible.

Check Contents

If all user accounts are authenticated by the OS or an enterprise-level authentication/access mechanism, and not by Oracle, this is not a finding.

If an Oracle feature/product, an OS feature, a third-party product, or custom code is used to automate account management, this is not a finding.

If there are any accounts managed by the Oracle Database, review the system documentation for justification and approval of these accounts.

If any Oracle-managed accounts exist that are not documented and approved, this is a finding.

Vulnerability Number

V-270499

Documentable

False

Rule Version

O19C-00-000800

Severity Override Guidance

If all user accounts are authenticated by the OS or an enterprise-level authentication/access mechanism, and not by Oracle, this is not a finding.

If an Oracle feature/product, an OS feature, a third-party product, or custom code is used to automate account management, this is not a finding.

If there are any accounts managed by the Oracle Database, review the system documentation for justification and approval of these accounts.

If any Oracle-managed accounts exist that are not documented and approved, this is a finding.

Check Content Reference

M

Target Key

5672