STIGQter STIGQter: STIG Summary: Oracle Database 12c Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Apr 2021:

DBMS production application and data directories must be protected from developers on shared production/development DBMS host systems.

DISA Rule

SV-219852r401224_rule

Vulnerability Number

V-219852

Group Title

SRG-APP-000516-DB-000363

Rule Version

O121-BP-024100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Create separate DBMS host OS groups for developer and production DBAs.

Do not assign production DBA OS group membership to accounts used for development.

Remove development accounts from production DBA OS group membership.

Recommend establishing a dedicated DBMS host for production DBMS installations. A dedicated host system in this case refers to an instance of the operating system at a minimum. The operating system may reside on a virtual host machine where supported by the DBMS vendor.

Check Contents

If the DBMS or DBMS host is not shared by production and development activities, this check is not a finding.

Review OS DBA group membership.

If any developer accounts, as identified in the System Security Plan, have been assigned DBA privileges, this is a finding.

Note: Though shared production/non-production DBMS installations was allowed under previous database STIG guidance, doing so may place it in violation of OS, Application, Network or Enclave STIG guidance. Ensure that any shared production/non-production DBMS installation meets STIG guidance requirements at all levels or mitigate any conflicts in STIG guidance with the AO.

Vulnerability Number

V-219852

Documentable

False

Rule Version

O121-BP-024100

Severity Override Guidance

If the DBMS or DBMS host is not shared by production and development activities, this check is not a finding.

Review OS DBA group membership.

If any developer accounts, as identified in the System Security Plan, have been assigned DBA privileges, this is a finding.

Note: Though shared production/non-production DBMS installations was allowed under previous database STIG guidance, doing so may place it in violation of OS, Application, Network or Enclave STIG guidance. Ensure that any shared production/non-production DBMS installation meets STIG guidance requirements at all levels or mitigate any conflicts in STIG guidance with the AO.

Check Content Reference

M

Target Key

4059

Comments