5.19 Enable 'PROCEDURE' Audit Option

Information

Any unauthorized attempts to create or drop a procedure in another's schema should cause concern, whether successful or not. Changes to critical store code can dramatically change the behavior of the application and produce serious security consequences, including privilege escalation and introducing SQL injection vulnerabilities. Audit records of such changes can be helpful in forensics.

Solution

Execute the following SQL statement to remediate this setting. AUDIT PROCEDURE;

See Also

https://workbench.cisecurity.org/files/601

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: OracleDB

Control ID: 3cf41a2047346cecbebd1face9f1827ffb659c252f0f05d6f43e358c6a231426