Item Search

NameAudit NamePluginCategory
DG0004-ORACLE11 - Application object owner accounts should be disabled when not performing installation or maintenance actions.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

CONFIGURATION MANAGEMENT

DG0005-ORACLE11 - Only necessary privileges to the host system should be granted to DBA OS accounts - 'Oracle instance DBA is only a member of ORA_{SID}_DBA and Users group'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

ACCESS CONTROL

DG0012-ORACLE11 - Database software directories including DBMS configuration files are stored in dedicated directories separate from the host OS and other applications - 'ORACLE_BASE environment variable set'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0012-ORACLE11 - Database software directories including DBMS configuration files are stored in dedicated directories separate from the host OS and other applications - 'ORACLE_HOME environment variable set'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0014-ORACLE11 - Default demonstration and sample database objects and applications should be removed - 'No demo or sample users exist'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

CONFIGURATION MANAGEMENT

DG0025-ORACLE11 - DBMS cryptography must be NIST FIPS 140-2 validated - '$ORACLE_HOME/network/admin/sqlnet.ora SSL_CIPHER_SUITES is configured'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

DG0040-ORACLE11 - The DBMS software installation account should be restricted to authorized users - '$ORACLE_HOME owner, group and permissions are configured'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONFIGURATION MANAGEMENT

DG0040-ORACLE11 - The DBMS software installation account should be restricted to authorized users - 'Oracle install account is disabled'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

ACCESS CONTROL

DG0060-ORACLE11 - All database non-interactive, n-tier connection, and shared accounts that exist should be documented and approved by the IAO.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DG0070-ORACLE11 - Unauthorized user accounts should not exist.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DG0077-ORACLE11 - Production databases should be protected from unauthorized access by developers on shared production/development host systems.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DG0098-ORACLE11 - ccess to external objects should be disabled if not required and authorized - 'utl_file_dir does not include *'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

CONFIGURATION MANAGEMENT

DG0099-ORACLE11 - Access to external DBMS executables should be disabled or restricted - '$ORACLE_HOME/network/admin/tnsnames.ora KEY=EXTPROC does not exist'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONFIGURATION MANAGEMENT

DG0099-ORACLE11 - Access to external DBMS executables should be disabled or restricted - no PROGRAMS = EXTPROC' - tnsnames.oraDISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0110-ORACLE11 - The DBMS should not share a host supporting an independent security service.DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONFIGURATION MANAGEMENT

DG0117-ORACLE11 - Administrative privileges should be assigned to database accounts via database roles.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DG0123-ORACLE11 - Access to DBMS system tables and other configuration or metadata should be restricted to DBAs.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DG0152-ORACLE11 - DBMS network communications should comply with PPS usage restrictions - PORT = 1521, 1575, 1830, 2481, 2482, 2483 or 2484' - cman.oraDISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0152-ORACLE11 - DBMS network communications should comply with PPS usage restrictions - PORT = 1521, 1575, 1830, 2481, 2482, 2483 or 2484' - listener.oraDISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0191-ORACLE11 - Credentials used to access remote databases should be protected by encryption and restricted to authorized users - '$ORACLE_HOME/network/admin/sqlnet.ora WALLET_LOCATION does not exist'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

IDENTIFICATION AND AUTHENTICATION

DO0190-ORACLE11 - The audit table should be owned by SYS or SYSTEM - 'Audit table owner = SYS or SYSTEM'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

AUDIT AND ACCOUNTABILITY

DO0286-ORACLE11 - The Oracle INBOUND_CONNECT_TIMEOUT and SQLNET.INBOUND_CONNECT_TIMEOUT parameters should be set to a value greater than 0 - '%ORACLE_HOME%\NETWORK\ADMIN\SQLNET.ORA SQLNET.INBOUND_CONNECT_TIMEOUT > 0'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

ACCESS CONTROL

DO0286-ORACLE11 - The Oracle INBOUND_CONNECT_TIMEOUT and SQLNET.INBOUND_CONNECT_TIMEOUT parameters should be set to a value greater than 0 - '$ORACLE_HOME/network/admin/sqlnet.ora SQLNET.INBOUND_CONNECT_TIMEOUT = 0'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

ACCESS CONTROL

DO0287-ORACLE11 - The Oracle SQLNET.EXPIRE_TIME parameter should be set to a value greater than 0 - '%ORACLE_HOME%\NETWORK\ADMIN\SQLNET.ORA SQLNET.EXPIRE_TIME > 0'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

ACCESS CONTROL

DO0320-ORACLE11 - Application role permissions should not be assigned to the Oracle PUBLIC role - 'PUBLIC role has no granted roles'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DO3609-ORACLE11 - System privileges granted using the WITH ADMIN OPTION should not be granted to unauthorized user accounts - 'No accounts granted with admin option exist'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DO3610-ORACLE11 - Required object auditing should be configured - 'Auditing for update and delete is enabled'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

AUDIT AND ACCOUNTABILITY

DO3689-ORACLE11 - Object permissions granted to PUBLIC should be restricted.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DO5037-ORACLE11 - Oracle SQLNet and listener log files should not be accessible to unauthorized users - '%ORACLE_HOME%\NETWORK\ADMIN\listener.ora DIAG_ADR_ENABLED_[listener name] = ON'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

AUDIT AND ACCOUNTABILITY

DO5037-ORACLE11 - Oracle SQLNet and listener log files should not be accessible to unauthorized users - '%ORACLE_HOME%\NETWORK\ADMIN\listener.ora LOG_DIRECTORY_{listener} is configured'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

AUDIT AND ACCOUNTABILITY

DO5037-ORACLE11 - Oracle SQLNet and listener log files should not be accessible to unauthorized users - '%ORACLE_HOME%\NETWORK\ADMIN\listener.ora LOG_FILE_{listener} is configured'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

AUDIT AND ACCOUNTABILITY

DO5037-ORACLE11 - Oracle SQLNet and listener log files should not be accessible to unauthorized users - 'listener.ora TRACE_DIRECTORY_{listener} is configured'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

AUDIT AND ACCOUNTABILITY

DO5037-ORACLE11 - Oracle SQLNet and listener log files should not be accessible to unauthorized users - 'LOG_FILE_SERVER = sqlnet'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

AUDIT AND ACCOUNTABILITY

DO6740-ORACLE11 - The Oracle Listener ADMIN_RESTRICTIONS parameter if present should be set to ON - '$ORACLE_HOME/network/admin/listener.ora ADMIN_RESTRICTIONS_{listener} = on'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

DO6747-ORACLE11 - Remote administration should be disabled for the Oracle connection manager - '%ORACLE_HOME%\NETWORK\ADMIN\CMAN.ORA REMOTE_ADMIN = no'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

ACCESS CONTROL

DO6747-ORACLE11 - Remote administration should be disabled for the Oracle connection manager - '$ORACLE_HOME/network/admin/cman.ora does not exist'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONFIGURATION MANAGEMENT

DO6754-ORACLE11 - Oracle Configuration Manager should not remain installed on a production system - '$ORACLE_HOME/ccr does not exist'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONFIGURATION MANAGEMENT

DTBI113 - The Download unsigned ActiveX controls property must be disallowed (Restricted Site zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTBI115 - ActiveX controls and plug-ins must be disallowed (Restricted Sites zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTBI740 - Managing SmartScreen Filter use must be enforced.DISA STIG Microsoft Internet Explorer 9 v1r15Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WA000-WI030 IIS6 - The IUSR_machinename account must not have read access to the .inc files or their equivalent. - '.asa'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WI100 IIS6 - The File System Object component, if not required, must be disabled. - 'Scripting.FileSystemObject Check'DISA STIG IIS 6.0 Server v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI6020 IIS6 - The Recycle Worker processes in minutes monitor must be set properly.DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI6024 IIS6 - The maximum virtual memory monitor must be enabled.DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI6032 IIS6 - The Enable pinging monitor must be enabled. - 'PingInterval set to 30 or more'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI6080 IIS6 - The AllowRestrictedChars registry key must be disabled.DISA STIG IIS 6.0 Server v6r16Windows

SYSTEM AND INFORMATION INTEGRITY

WA000-WI6082 IIS6 - The EnableNonUTF8 registry key must be disabled.DISA STIG IIS 6.0 Server v6r16Windows

SYSTEM AND INFORMATION INTEGRITY

WA000-WI6094 IIS6 - The UriMaxUriBytes registry entry must be set properly.DISA STIG IIS 6.0 Server v6r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WA000-WI6098 IIS6 - The MaxRequestEntityAllowed metabase value must be defined. - 'IisWebServerSetting'DISA STIG IIS 6.0 Site Checklist v6r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WG140 IIS6 - A private web sites authentication mechanism must use client certificates. - 'AccessSSL Enabled'DISA STIG IIS 6.0 Site Checklist v6r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION