6.1.6 Ensure the 'PUBLIC DATABASE LINK' Audit Option Is Enabled

Information

The PUBLIC DATABASE LINK object allows for the creation of a public link for an application-based 'user' to access the database for connections/session creation. Enabling the audit option causes all user activities involving the creation, alteration, or dropping of public links to be audited.

Rationale:

As the logging of user activities involving the creation, alteration, or dropping of a PUBLIC DATABASE LINK can provide forensic evidence about a pattern of unauthorized activities, the audit capability should be enabled.

Solution

To remediate this setting, execute the following SQL statement in either the non multi-tenant or container database, it does NOT need run in the pluggable.

AUDIT PUBLIC DATABASE LINK;

See Also

https://workbench.cisecurity.org/files/2741