SV-238468r667578_rule
V-238468
SRG-APP-000164-DB-000401
O112-C2-014900
CAT II
10
Implement procedures for assigning temporary passwords to user accounts.
Procedures should include instructions to meet current DoD password length and complexity requirements and provide a secure method to relay the temporary password to the user.
If all user accounts are authenticated by the OS or an enterprise-level authentication/access mechanism, and not by Oracle, stop here: this is not a finding against the DBMS.
Where accounts are authenticated using passwords, review procedures and implementation evidence for creation of temporary passwords. If the procedures or evidence do not exist or do not enforce passwords to meet DoD password requirements, this is a finding.
V-238468
False
O112-C2-014900
If all user accounts are authenticated by the OS or an enterprise-level authentication/access mechanism, and not by Oracle, stop here: this is not a finding against the DBMS.
Where accounts are authenticated using passwords, review procedures and implementation evidence for creation of temporary passwords. If the procedures or evidence do not exist or do not enforce passwords to meet DoD password requirements, this is a finding.
M
4057