DG0019: DBMS software ownership

Information

File and directory ownership imparts full privileges to the owner. These privileges should be restricted to a single, dedicated account to preserve proper chains of ownership and privilege assignment management.

Solution

Assign DBMS file and directory ownership to a dedicated Oracle OS owner account.

Document the locations of Oracle DBMS files and directories in the System Security Plan.

On UNIX systems:

Assign DBMS file and directory ownership to a dedicated Oracle host OS software installation and maintenance account.

The owner and group ownership as well as file permissions for the following files (if present) should not be changed:

extjob
jssu
nmb
nmhs
nmo
oradism
externaljob.ora
coraenv
dbhome
oraenv

Using the dedicated Oracle host OS software installation and maintenance account to install and maintain the DBMS software libraries and configuration files will help maintain file and directory ownership.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Oracle_Database_11g_V8R19_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|III, CSCv6|3.1, Rule-ID|SV-24363r1_rule, STIG-ID|DG0019-ORACLE11, Vuln-ID|V-3805

Plugin: Unix

Control ID: 7c27c2d09ee50ae3170baa1427ccb2e4a41d81a86ee7b0b23be9817c078c4da2