5.14 Enable 'SELECT ANY DICTIONARY' Audit Option

Information

As the logging of user activities involving the capability to access the description of all schema objects in the database can provide forensic evidence about a pattern of unauthorized activities, the audit capability should be set according to the needs of the organization.

Solution

Execute the following SQL statement to remediate this setting. AUDIT SELECT ANY DICTIONARY;

See Also

https://workbench.cisecurity.org/files/601

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: OracleDB

Control ID: 99482c524de9b05a9c76d930d9568e1ba843d764f794a30cd409553208607a81