SV-24501r2_rule
V-3847
Oracle storage use privileges
DO0157-ORACLE11
CAT III
10
Assign tablespace quotas only to database accounts authorized to create and or own objects in the database.
Document authorized tablespace quotas for all accounts authorized to own objects in the System Security Plan.
Remove any quotas assigned to application users, application administrators, or any other unauthorized accounts.
From SQL*Plus:
alter user [username] quota 0 on [tablespace name];
Replace [username] with the named user and [tablespace name] with the identified tablespace name.
From SQL*Plus:
select username, tablespace_name from dba_ts_quotas
where username not in (select distinct owner from dba_objects)
and username not in
(select grantee from dba_role_privs where granted_role='DBA');
Review the list of user names returned.
If any belong to application users or application administrators, this is a Finding.
V-3847
True
DO0157-ORACLE11
From SQL*Plus:
select username, tablespace_name from dba_ts_quotas
where username not in (select distinct owner from dba_objects)
and username not in
(select grantee from dba_role_privs where granted_role='DBA');
Review the list of user names returned.
If any belong to application users or application administrators, this is a Finding.
M
Database Administrator
1367