DG0118-ORACLE11 - The IAM should review changes to DBA role assignments.

Information

Unauthorized assignment of DBA privileges can lead to a compromise of DBMS integrity. Providing oversight to the authorization and assignment of privileges provides the separation of duty to support sufficient oversight.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Develop, document and implement procedures to monitor changes to DBA role assignments.

Develop, document and implement procedures to notify the IAM of changes to DBA role assignments.

Include in the procedures methods that provide evidence of monitoring and notification.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-24742r1_rule, STIG-ID|DG0118-ORACLE11, Vuln-ID|V-15127

Plugin: Unix

Control ID: 426ab36ec039b5ff80a82a27e2d51daf61c045c01afbfbf4995c950720842877