DO0190-ORACLE11 - The audit table should be owned by SYS or SYSTEM - 'Audit table owner = SYS or SYSTEM'

Information

Audit data is frequently targeted by malicious users as it can provide a means to detect their activity. The protection of the audit trail data is of special concern and requires restrictions to allow only the auditor and DBMS backup, recovery, and maintenance users access to it.

Solution

Change the owner of the $AUD table to SYS or SYSTEM account.

OR

Recreate the audit table while logged in as SYS or SYSTEM.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c., CAT|II, Rule-ID|SV-24859r2_rule, STIG-ID|DO0190-ORACLE11, Vuln-ID|V-2515

Plugin: OracleDB

Control ID: ded7fe38c82ad7153b846939a5d226660df386d16eb851218268627f325b850d