STIGQter STIGQter: STIG Summary: Oracle Database 11g Installation STIG Version: 8 Release: 20 Benchmark Date: 28 Jul 2017:

Remote administrative access to the database should be monitored by the IAO or IAM.

DISA Rule

SV-24810r1_rule

Vulnerability Number

V-15118

Group Title

Review of DBMS remote administrative access

Rule Version

DG0159-ORACLE11

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Develop, document and implement policy and procedures to monitor remote administrative access to the DBMS.

The automated generation of a log report with automatic dissemination to the IAO/IAM may be used.

Require and store an acknowledgement of receipt and confirmation of review for the log report.

Check Contents

If remote administrative access to the database is prohibited and is disabled (See Check DG0093), this check is Not a Finding.

Review policy, procedure and evidence of implementation for monitoring of remote administrative access to the database.

If monitoring procedures for remote administrative access are not documented or implemented, this is a Finding.

Vulnerability Number

V-15118

Documentable

False

Rule Version

DG0159-ORACLE11

Severity Override Guidance

If remote administrative access to the database is prohibited and is disabled (See Check DG0093), this check is Not a Finding.

Review policy, procedure and evidence of implementation for monitoring of remote administrative access to the database.

If monitoring procedures for remote administrative access are not documented or implemented, this is a Finding.

Check Content Reference

I

Responsibility

Information Assurance Officer

Target Key

1368

Comments