SV-24798r1_rule
V-15642
DBMS access to sensitive data
DG0138-ORACLE11
CAT II
10
Define, document and implement all sensitive data access controls based on job function in the System Security Plan.
If no data is identified as being sensitive or classified by the Information Owner, in the System Security Plan or in the AIS Functional Architecture documentation, this check is Not a Finding.
if no identified sensitive or classified data requires encryption by the Information Owner in the System Security Plan and/or AIS Functional Architecture documentation, this check is Not a Finding.
Review data access requirements for sensitive data as identified and assigned by the Information Owner in the System Security Plan.
Review the access controls for sensitive data configured in the database.
If the configured access controls do not match those defined in the System Security Plan, this is a Finding.
V-15642
False
DG0138-ORACLE11
If no data is identified as being sensitive or classified by the Information Owner, in the System Security Plan or in the AIS Functional Architecture documentation, this check is Not a Finding.
if no identified sensitive or classified data requires encryption by the Information Owner in the System Security Plan and/or AIS Functional Architecture documentation, this check is Not a Finding.
Review data access requirements for sensitive data as identified and assigned by the Information Owner in the System Security Plan.
Review the access controls for sensitive data configured in the database.
If the configured access controls do not match those defined in the System Security Plan, this is a Finding.
I
Database Administrator
1367