5.16 Enable 'GRANT ANY PRIVILEGE' Audit Option

Information

GRANT ANY PRIVILEGE allows a user to grant any system privilege, including the most powerful privileges typically available only to administrators - to change the security infrastructure, to drop/add/modify users and more. Auditing the use of this privilege is part of a comprehensive auditing policy that can help in detecting issues and can be useful in forensics.

Solution

Execute the following SQL statement to remediate this setting. AUDIT GRANT ANY PRIVILEGE;

See Also

https://workbench.cisecurity.org/files/601

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: OracleDB

Control ID: f85be94a0bed17c54ab0e753576e5ff850935519a5ab6703312ca4254b102ecc