DG0167-ORACLE11 - Sensitive data served by the DBMS should be protected by encryption when transmitted across the network.

Information

Sensitive data served by the DBMS and transmitted across the network in clear text is vulnerable to unauthorized capture and review.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure encryption of sensitive data served by the DBMS in accordance with the specifications provided in the System Security Plan and AIS Functional Architecture documentation.

Document acceptance of risk by the Information Owner where sensitive or classified data is not encrypted.

Have the IAO document assurance that the unencrypted sensitive or classified information is otherwise inaccessible to those who do not have Need-to-Know access to the data.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

References: CAT|I, Rule-ID|SV-24821r1_rule, STIG-ID|DG0167-ORACLE11, Vuln-ID|V-15104

Plugin: Unix

Control ID: 909ab6e3e66193814318f9c64e824da3cb57f6157a64b5d57836fab40c8e6eb8