2.1.3 Ensure 'ADMIN_RESTRICTIONS_' Is Set to 'ON'

Information

The admin_restrictions_ setting in the 'listener.ora' file can require that any attempted real-time alteration of the parameters in the 'listener' via the 'set' command file be refused unless the 'listener.ora' file is manually altered, then restarted by a privileged user.

Rationale:
Blocking unprivileged users from making alterations of the 'listener.ora' file, where remote data/service settings are specified, will help protect data confidentiality.

Solution

To remediate this recommendation:

Use a text editor such as 'vi' to set the admin_restrictions_ to the value 'ON'.

See Also

https://workbench.cisecurity.org/files/2121

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(1), CSCv6|5.1

Plugin: Windows

Control ID: 93d60cae3daa021059393d0d54ae2a2dad6486f93ed7bc709a98e51c7946524f