DO0350-ORACLE11 - Oracle system privileges should not be directly assigned to unauthorized accounts.

Information

System privileges allow system-wide changes to the database or database objects. Unauthorized use of system privileges may jeopardize production applications, application data, or the database configuration and operation.

Solution

Document and justify system privileges assigned to users/roles in the System Security Plan and authorize with the IAO.

Remove unauthorized or unjustified system privileges from user accounts or roles.

From SQL*Plus:

revoke [privilege] from [user or role name];

Replace [privilege] with the named privilege and [user or role name] with the identified user or role.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, Rule-ID|SV-24534r2_rule, STIG-ID|DO0350-ORACLE11, Vuln-ID|V-3439

Plugin: OracleDB

Control ID: aaba12e9386fdcad3b561850aa6059ea2f1698c0dcaedf470920d8a34fce3813