STIGQter STIGQter: STIG Summary:

Oracle Database 19c Security Technical Implementation Guide

Version: 1

Release: 5 Benchmark Date: 01 Apr 2026

CheckedNameTitle
SV-270495r1167748_ruleOracle Database must limit the number of concurrent sessions for each system account to an organization-defined number of sessions.
SV-270496r1167727_ruleOracle Database must protect against or limit the effects of organization-defined types of denial-of-service (DoS) attacks.
SV-270497r1167730_ruleOracle Database must automatically terminate a user session after organization-defined conditions or trigger events requiring session disconnect.
SV-270498r1167732_ruleOracle Database must associate organization-defined types of security labels having organization-defined security label values with information in storage.
SV-270499r1064775_ruleOracle Database must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.
SV-270500r1167734_ruleOracle Database must enforce approved authorizations for logical access to the system in accordance with applicable policy.
SV-270501r1167736_ruleOracle Database must protect against an individual who uses a shared account falsely denying having performed a particular action.
SV-270502r1167738_ruleOracle Database must provide audit record generation capability for organization-defined auditable events within the database.
SV-270503r1064787_ruleOracle Database must allow designated organizational personnel to select which auditable events are to be audited by the database.
SV-270504r1167741_ruleOracle Database must generate audit records for the DOD-selected list of auditable events, when successfully accessed, added, modified, or deleted, to the extent such information is available.
SV-270505r1167742_ruleOracle Database must include organization-defined additional, more detailed information in the audit records for audit events identified by type, location, or subject.
SV-270506r1167744_ruleOracle Database must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
SV-270507r1065200_ruleOracle Database must off-load audit data to a separate log management facility; this must be continuous and in near-real-time for systems with a network connection to the storage facility, and weekly or more often for stand-alone systems.
SV-270508r1065201_ruleThe Oracle Database, or the logging or alerting mechanism the application uses, must provide a warning when allocated audit record storage volume record storage volume reaches 75 percent of maximum audit record storage capacity.
SV-270509r1065202_ruleOracle Database must provide an immediate real-time alert to appropriate support staff of all audit log failures.
SV-270510r1068294_ruleThe audit information produced by the Oracle Database must be protected from unauthorized access, modification, or deletion.
SV-270511r1065262_ruleThe system must protect audit tools from unauthorized access, modification, or deletion.
SV-270512r1065305_ruleOracle Database must support enforcement of logical access restrictions associated with changes to the database management system (DBMS) configuration and to the database itself.
SV-270513r1138543_ruleOracle Database products must be a version supported by the vendor.
SV-270514r1064820_ruleDatabase software, applications, and configuration files must be monitored to discover unauthorized changes.
SV-270515r1065210_ruleThe OS must limit privileges to change the database management system (DBMS) software resident within software libraries (including privileged programs).
SV-270516r1064826_ruleThe Oracle Database software installation account must be restricted to authorized users.
SV-270517r1064829_ruleDatabase software directories, including database management system (DBMS) configuration files, must be stored in dedicated directories, or DASD pools, separate from the host OS and other applications.
SV-270518r1064832_ruleDatabase objects must be owned by accounts authorized for ownership.
SV-270519r1112463_ruleThe role(s)/group(s) used to modify database structure (including but not necessarily limited to tables, indexes, storage, etc.) and logic modules (stored procedures, functions, triggers, links to software external to the DBMS, etc.) must be restricted to authorized users.
SV-270520r1115964_ruleOracle Database must be configured in accordance with the security configuration settings based on DOD security configuration and implementation guidance, including STIGs, NSA configuration guides, CTOs, DTMs, and IAVMs.
SV-270521r1112467_ruleOracle instance names must not contain Oracle version numbers.
SV-270522r1115956_ruleFixed user and PUBLIC Database links must be authorized for use.
SV-270523r1167746_ruleThe Oracle WITH GRANT OPTION privilege must be limited when granted to nondatabase administrator (DBA) or nonapplication administrator user accounts.
SV-270524r1112471_ruleThe Oracle REMOTE_OS_ROLES parameter must be set to FALSE.
SV-270525r1112473_ruleThe Oracle SQL92_SECURITY parameter must be set to TRUE.
SV-270526r1115966_ruleThe Oracle password file ownership and permissions should be limited and the REMOTE_LOGIN_PASSWORDFILE parameter must be set to EXCLUSIVE or NONE.
SV-270527r1065266_ruleSystem privileges granted using the WITH ADMIN OPTION must not be granted to unauthorized user accounts.
SV-270528r1064862_ruleSystem Privileges must not be granted to PUBLIC.
SV-270529r1065268_ruleOracle roles granted using the WITH ADMIN OPTION must not be granted to unauthorized accounts.
SV-270530r1065320_ruleObject permissions granted to PUBLIC must be restricted.
SV-270531r1065272_ruleThe Oracle Listener must be configured to require administration authentication.
SV-270532r1064874_ruleApplication role permissions must not be assigned to the Oracle PUBLIC role.
SV-270533r1065215_ruleOracle application administration roles must be disabled if not required and authorized.
SV-270534r1065274_ruleThe directories assigned to the LOG_ARCHIVE_DEST* parameters must be protected from unauthorized access.
SV-270535r1065307_ruleThe Oracle _TRACE_FILES_PUBLIC parameter if present must be set to FALSE.
SV-270536r1064886_ruleOracle Database production application and data directories must be protected from developers on shared production/development database management system (DBMS) host systems.
SV-270537r1064889_ruleUse of the Oracle Database installation account must be logged.
SV-270538r1064892_ruleThe Oracle Database data files, transaction logs and audit files must be stored in dedicated directories or disk partitions separate from software or other application files.
SV-270539r1064895_ruleNetwork access to Oracle Database must be restricted to authorized personnel.
SV-270540r1064898_ruleChanges to configuration options must be audited.
SV-270541r1065276_ruleThe /diag subdirectory under the directory assigned to the DIAGNOSTIC_DEST parameter must be protected from unauthorized access.
SV-270542r1064904_ruleRemote administration must be disabled for the Oracle connection manager.
SV-270543r1064907_ruleNetwork client connections must be restricted to supported versions.
SV-270544r1065278_ruleDatabase administrator (DBA) OS accounts must be granted only those host system privileges necessary for the administration of the Oracle Database.
SV-270545r1064913_ruleOracle Database default accounts must be assigned custom passwords.
SV-270546r1112478_ruleOracle Database must provide a mechanism to automatically identify accounts designated as temporary or emergency accounts.
SV-270547r1064919_ruleOracle Database must provide a mechanism to automatically remove or disable temporary user accounts after 72 hours.
SV-270548r1064922_ruleOracle Database must be protected from unauthorized access by developers on shared production/development host systems.
SV-270549r1112480_ruleOracle Database must verify account lockouts persist until reset by an administrator.
SV-270550r1112482_ruleOracle Database must set the maximum number of consecutive invalid logon attempts to three.
SV-270551r1112483_ruleOracle Database must disable user accounts after 35 days of inactivity.
SV-270552r1064934_ruleOracle Database default demonstration and sample databases, database objects, and applications must be removed.
SV-270553r1064937_ruleUnused database components, database management system (DBMS) software, and database objects must be removed.
SV-270554r1065221_ruleUnused database components that are integrated in the database management system (DBMS) and cannot be uninstalled must be disabled.
SV-270555r1115550_ruleOS accounts used to run external procedures called by Oracle Database must have limited privileges.
SV-270556r1064946_ruleUse of external executables must be authorized.
SV-270557r1065281_ruleAccess to external executables must be disabled or restricted.
SV-270558r1065283_ruleOracle Database must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL) and vulnerability assessments.
SV-270559r1068298_ruleOracle Database must ensure users are authenticated with an individual authenticator prior to using a shared authenticator.
SV-270560r1065286_ruleOracle Database must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
SV-270561r1112485_ruleOracle Database must enforce the DOD standards for password complexity.
SV-270562r1064964_ruleProcedures for establishing temporary passwords that meet DOD password requirements for new accounts must be defined, documented, and implemented.
SV-270563r1064967_ruleOracle Database must enforce password maximum lifetime restrictions.
SV-270564r1136919_ruleOracle Database must, for password-based authentication, store passwords using an approved salted key derivation function, preferably using a keyed hash.
SV-270565r1136921_ruleIf passwords are used for authentication, the Oracle Database must transmit only encrypted representations of passwords.
SV-270566r1136923_ruleOracle Database, when using public key infrastructure (PKI)-based authentication, must enforce authorized access to the corresponding private key.
SV-270567r1064979_ruleOracle Database must map the authenticated identity to the user account using public key infrastructure (PKI)-based authentication.
SV-270568r1136925_ruleWhen using command-line tools such as Oracle SQL*Plus, which can accept a plain-text password, users must use an alternative logon method that does not expose the password.
SV-270569r1065205_ruleOracle Database must use NIST-validated FIPS 140-2/140-3 compliant cryptography for authentication mechanisms.
SV-270570r1065294_ruleOracle Database must uniquely identify and authenticate nonorganizational users (or processes acting on behalf of nonorganizational users).
SV-270571r1137664_ruleOracle Database must implement NIST FIPS 140-2/140-3 validated cryptographic modules to protect unclassified information requiring confidentiality and cryptographic protection, in accordance with the data owner's requirements.
SV-270572r1137655_ruleOracle Database must separate user functionality (including user interface services) from database management functionality.
SV-270573r1064997_ruleOracle Database must preserve any organization-defined system state information in the event of a system failure.
SV-270574r1192921_ruleOracle Database must take steps to protect data at rest and ensure confidentiality and integrity of application data.
SV-270575r1065003_ruleOracle Database must implement cryptographic mechanisms to prevent unauthorized modification of organization-defined information at rest (to include, at a minimum, PII and classified information) on organization-defined information system components.
SV-270576r1065006_ruleOracle Database must isolate security functions from nonsecurity functions by means of separate security domains.
SV-270577r1137656_ruleOracle Database contents must be protected from unauthorized and unintended information transfer by enforcement of a data-transfer policy.
SV-270578r1137658_ruleAccess to Oracle Database files must be limited to relevant processes and to authorized, administrative users.
SV-270579r1065015_ruleOracle Database must employ cryptographic mechanisms preventing the unauthorized disclosure of information during transmission unless the transmitted data is otherwise protected by alternative physical measures.
SV-270580r1068300_ruleOracle Database must check the validity of data inputs.
SV-270581r1065225_ruleThe database management system (DBMS) and associated applications must reserve the use of dynamic code execution for situations that require it.
SV-270582r1065226_ruleThe database management system (DBMS) and associated applications, when making use of dynamic code execution, must take steps against invalid values that may be used in a SQL injection attack, therefore resulting in steps to prevent a SQL injection attack.
SV-270583r1065027_ruleOracle Database must only generate error messages that provide information necessary for corrective actions without revealing organization-defined sensitive or potentially harmful information in error logs and administrative messages that could be exploited.
SV-270584r1065296_ruleOracle Database must restrict error messages so only authorized personnel may view them.
SV-270585r1137667_ruleOracle Database software must be evaluated and patched against newly found vulnerabilities.
SV-270587r1112489_ruleOracle Database must, for password-based authentication, verify that when users create or update passwords, the passwords are not found on the list of commonly used, expected, or compromised passwords in IA-5 (1) (a).
SV-270588r1065042_ruleOracle Database must, for password-based authentication, require immediate selection of a new password upon account recovery.
SV-270589r1136927_ruleOracle Database must include only approved trust anchors in trust stores or certificate stores managed by the organization.
SV-275999r1115962_ruleA minimum of three Oracle Control Files must be created and each stored on a separate physical and logical device.
SV-276000r1112495_ruleA minimum of three Oracle redo log groups/files must be defined and configured to be stored on separate, archived physical disks or archived directories on a RAID device. In addition, each Oracle redo log group must have a minimum of two Oracle redo log members (files).