SV-24437r1_rule
V-15150
DBMS System Security Plan
DG0154-ORACLE11
CAT III
10
Develop, document and implement a System Security Plan for the DBMS.
Include IA documentation related to the DBMS in the System Security Plan for the system that the DBMS supports.
Review section 3.4 - System Security Plan Overview in the ORACLE DATABASE SECURITY CHECKLIST for more information.
Review the System Security Plan for the DBMS.
Review coverage of the following in the System Security Plan:
- Technical, administrative and procedural IA program and policies that govern the DBMS
- Identification of all IA personnel (IAM, IAO, DBA, SA) assigned responsibility to the DBMS
- Specific IA requirements and objectives (e.g., requirements for data handling or dissemination (to include identification of sensitive data stored in the database, database application user job functions/roles and privileges), system redundancy and backup, or emergency response)
If a System Security Plan does not exist or does not identify or reference all relevant security controls, this is a Finding.
V-15150
False
DG0154-ORACLE11
Review the System Security Plan for the DBMS.
Review coverage of the following in the System Security Plan:
- Technical, administrative and procedural IA program and policies that govern the DBMS
- Identification of all IA personnel (IAM, IAO, DBA, SA) assigned responsibility to the DBMS
- Specific IA requirements and objectives (e.g., requirements for data handling or dissemination (to include identification of sensitive data stored in the database, database application user job functions/roles and privileges), system redundancy and backup, or emergency response)
If a System Security Plan does not exist or does not identify or reference all relevant security controls, this is a Finding.
I
Information Assurance Officer
1368