5.20 Enable 'ALTER SYSTEM' Audit Option

Information

Alter system allows one to change instance settings, including security settings and auditing options. Additionally alter system can be used to run operating system commands using undocumented Oracle functionality. Any unauthorized attempt to alter the system should be cause for concern. Alterations outside of some specified maintenance window may be of concern. In forensics, these audit records could be quite useful.

Solution

Execute the following SQL statement to remediate this setting. AUDIT ALTER SYSTEM; Impact: The change to the check/audit is to ensure that the audit is in effect for all users regardless of proxy, whether successful or not. The previous Description was wrong - it is not 'auditing' that 'allows to modify the database settings'.

See Also

https://workbench.cisecurity.org/files/601

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: OracleDB

Control ID: 3f16a60bde2f3f0f77522711e0b0513ad775f1ffc4c254a903b90e98cea01d64