5.2 Enable 'ALTER USER' Audit Option

Information

As the logging of user activities involving the creation, alteration, or dropping of a USER can provide forensic evidence about a pattern of suspect/unauthorized activities, the audit capability should be set according to the needs of the organization.

Solution

Execute the following SQL statement to remediate this setting. AUDIT ALTER USER;

See Also

https://workbench.cisecurity.org/files/601

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: OracleDB

Control ID: 1c3a079e523f0bffcce02fec4038002daaee19cc9db750e5f4717629b0b60b50