STIGQter STIGQter: STIG Summary: Oracle Database 19c Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 01 Apr 2026:

Procedures for establishing temporary passwords that meet DOD password requirements for new accounts must be defined, documented, and implemented.

DISA Rule

SV-270562r1064964_rule

Vulnerability Number

V-270562

Group Title

SRG-APP-000164-DB-000401

Rule Version

O19C-00-014600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Implement procedures for assigning temporary passwords to user accounts.

Procedures should include instructions to meet current DOD password length and complexity requirements and provide a secure method to relay the temporary password to the user.

Check Contents

If all user accounts are authenticated by the OS or an enterprise-level authentication/access mechanism, and not by Oracle, this is not a finding.

Where accounts are authenticated using passwords, review procedures and implementation evidence for creation of temporary passwords.

If the procedures or evidence do not exist or do not enforce passwords to meet DOD password requirements, this is a finding.

Vulnerability Number

V-270562

Documentable

False

Rule Version

O19C-00-014600

Severity Override Guidance

If all user accounts are authenticated by the OS or an enterprise-level authentication/access mechanism, and not by Oracle, this is not a finding.

Where accounts are authenticated using passwords, review procedures and implementation evidence for creation of temporary passwords.

If the procedures or evidence do not exist or do not enforce passwords to meet DOD password requirements, this is a finding.

Check Content Reference

M

Target Key

5672