5.4 Enable 'ROLE' Audit Option

Information

Roles are a key database security infrastructure component. Any attempt to create, drop or alter a role should be audited. This statement auditing option also audits attempts, successful or not, to set a role in a session. Any unauthorized attempts to create, drop or alter a role may be worthy of investigation. Attempts to set a role by users without the role privilege may warrant investigation.

Solution

Execute the following SQL statement to remediate this setting: AUDIT ROLE; Impact: The change to the audit/check is to ensure that the audit is in effect for all users, regardless of proxy or success. The change to the title, description and rationale are to better clarify what it actually does. (e.g. It does NOT audit 'all ROLE activities/requests'. For example, it does not audit role grants and revokes.)

See Also

https://workbench.cisecurity.org/files/601

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: OracleDB

Control ID: ad7e7912400871d5000dbdb4de28048944d672452352049ac530faea526e1b64