SV-24639r1_rule
V-3811
DBMS temporary password procedures
DG0066-ORACLE11
CAT II
10
Develop, document and implement procedures for assigning, distributing and changing of temporary passwords for new database user accounts.
Procedures should include instruction that meet current DoD password length and complexity requirements and provide a secure method to relay the temporary password to the user.
Temporary passwords should also be short-lived and require immediate update by the user upon first use.
Consider using account authentication using certificates or other credentials in place of password authentication.
If all database accounts are configured to authenticate using certificates or other credentials besides passwords, this check is Not a Finding.
Review documented procedures and evidence of implementation for assignment of temporary passwords for password-authenticated accounts.
Confirm temporary passwords meet DoD password requirements.
Review documented procedures for distribution of temporary passwords to users.
Have the DBA demonstrate that the DBMS or applications accessing the database are configured to require a change of password by the user upon first use.
If documented procedures and evidence do not exist or are not complete, temporary passwords do not meet DoD password requirements, or the DBMS or applications accessing the database are not configured to require a change of password by the user upon first use, this is a Finding.
V-3811
False
DG0066-ORACLE11
If all database accounts are configured to authenticate using certificates or other credentials besides passwords, this check is Not a Finding.
Review documented procedures and evidence of implementation for assignment of temporary passwords for password-authenticated accounts.
Confirm temporary passwords meet DoD password requirements.
Review documented procedures for distribution of temporary passwords to users.
Have the DBA demonstrate that the DBMS or applications accessing the database are configured to require a change of password by the user upon first use.
If documented procedures and evidence do not exist or are not complete, temporary passwords do not meet DoD password requirements, or the DBMS or applications accessing the database are not configured to require a change of password by the user upon first use, this is a Finding.
I
Database Administrator
1368