DG0102: DBMS services dedicated custom account - 'No Oracle services are running as LocalSystem'

Information

Shared accounts do not provide separation of duties nor allow for assignment of least privileges for use by database processes and services. Without separation and least privilege, the exploit of one service or process is more likely to be able to compromise another or all other services.

Solution

On Windows Systems:

Create and assign a dedicated Oracle Windows OS account for all Oracle processes.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Oracle_Database_11g_V8R20_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-5, 800-53|AC-6, CAT|II, Rule-ID|SV-24702r2_rule, STIG-ID|DG0102-ORACLE11, Vuln-ID|V-15141

Plugin: Windows

Control ID: d4a10b31fbaec9b8fa818ed6aedb24b01a2af4c82068bab8c2d607eb61b067d1