DG0102: DBMS services dedicated custom account - 'dbsnmp services are using correct service account'

Information

Shared accounts do not provide separation of duties nor allow for assignment of least privileges for use by database processes and services. Without separation and least privilege, the exploit of one service or process is more likely to be able to compromise another or all other services.

Solution

On UNIX Systems:

Ensure the Oracle Owner account is used for all Oracle processes.

The Oracle SNMP agent (Intelligent or Management Agent) is required (by Oracle Corp per MetaLink Note 548928.1) to use the Oracle Process owner account.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Oracle_Database_11g_V8R20_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-5, 800-53|AC-6, CAT|II, Rule-ID|SV-24702r2_rule, STIG-ID|DG0102-ORACLE11, Vuln-ID|V-15141

Plugin: Unix

Control ID: 688ef6d67f4f42629293e361b4bdbb416fb69790c8d71249e4c08ffd144cada2