4.3.3 Ensure 'AUDIT SYSTEM' Is Revoked from Unauthorized 'GRANTEE'

Information

As assignment of the AUDIT SYSTEM privilege can allow the unauthorized alteration of system audit activities, disabling the creation of audit trails, this capability should be restricted according to the needs of the organization.

Solution

To remediate this setting execute the following SQL statement. REVOKE AUDIT SYSTEM FROM <grantee>;

See Also

https://workbench.cisecurity.org/files/601

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: OracleDB

Control ID: 40698e67d0765e54be2b37d0ef1c963cd0d36439c3059634f6756a6af7f6332d