DG0176-ORACLE11 - The DBMS audit logs should be included in backup operations.

Information

DBMS audit logs are essential to the investigation and prosecution of unauthorized access to the DBMS data. Unless audit logs are available for review, the extent of data compromise may not be determined and the vulnerability exploited may not be discovered. Undiscovered vulnerabilities could lead to additional or prolonged compromise of the data.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Document and implement locations of trace, log and alert locations in the System Security Plan.

Include all trace, log and alert files in regular backups.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-24825r1_rule, STIG-ID|DG0176-ORACLE11, Vuln-ID|V-15117

Plugin: Unix

Control ID: fd0bedf261c5ddf935d95cc3c85ec58a271cbfc577b9be05d4d35dff2d3ed804