SV-24606r1_rule
V-3803
DBMS shared production/development use
DG0017-ORACLE11
CAT II
10
Recommend establishing a dedicated DBMS host for production DBMS installations (See Checks DG0109 and DG0110).
A dedicated host system in this case refers to an instance of the operating system at a minimum.
The operating system may reside on a virtual host machine where supported by the DBMS vendor.
Review the System Security Plan and interview the DBA and IAO to determine if the DBMS host contains production and non-production DBMS installations.
If the DBMS host contains both production and non-production DBMS installations or the production DBMS installation is being used for non-production efforts, determine if this allowance is documented in the System Security Plan and authorized by the IAO.
If not documented and authorized, this is a Finding.
NOTE: Though shared production/non-production DBMS installations was allowed under previous database STIG guidance, doing so may place it in violation of OS, Application, Network or Enclave STIG guidance. Ensure that any shared production/non-production DBMS installations meets STIG guidance requirements at all levels or mitigate any conflicts in STIG guidance with your DAA.
V-3803
False
DG0017-ORACLE11
Review the System Security Plan and interview the DBA and IAO to determine if the DBMS host contains production and non-production DBMS installations.
If the DBMS host contains both production and non-production DBMS installations or the production DBMS installation is being used for non-production efforts, determine if this allowance is documented in the System Security Plan and authorized by the IAO.
If not documented and authorized, this is a Finding.
NOTE: Though shared production/non-production DBMS installations was allowed under previous database STIG guidance, doing so may place it in violation of OS, Application, Network or Enclave STIG guidance. Ensure that any shared production/non-production DBMS installations meets STIG guidance requirements at all levels or mitigate any conflicts in STIG guidance with your DAA.
I
Information Assurance Officer
1368