STIGQter STIGQter: STIG Summary: Oracle Database 11g Installation STIG Version: 8 Release: 20 Benchmark Date: 28 Jul 2017:

DBMS backup and restoration files should be protected from unauthorized access.

DISA Rule

SV-24637r1_rule

Vulnerability Number

V-15120

Group Title

DBMS backup and restoration file protection

Rule Version

DG0064-ORACLE11

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Develop, document and implement protection for backup and restoration files.

Document personnel and the level of access authorized for each to backup and restoration files and tools.

In addition to physical and host system protections, consider other methods including password protection of the files.

Check Contents

Review documented backup and restoration procedures to determine ownership and access during all phases of backup and recovery.

Review file protections assigned to online backup and restoration files and tools.

Review access, physical security protections and documented procedures for offline backup and restoration files and tools.

If implementation evidence indicates that backup or restoration files are subject to corruption, unauthorized access or physical loss, this is a Finding.

Vulnerability Number

V-15120

Documentable

False

Rule Version

DG0064-ORACLE11

Severity Override Guidance

Review documented backup and restoration procedures to determine ownership and access during all phases of backup and recovery.

Review file protections assigned to online backup and restoration files and tools.

Review access, physical security protections and documented procedures for offline backup and restoration files and tools.

If implementation evidence indicates that backup or restoration files are subject to corruption, unauthorized access or physical loss, this is a Finding.

Check Content Reference

I

Responsibility

Database Administrator

Target Key

1368

Comments