SV-24850r1_rule
V-2511
Oracle default account access
DO0140-ORACLE11
CAT II
10
Design, document and implement policy and procedures for use, logging and monitoring of Oracle default accounts in the System Security Plan.
Ensure those granted access to the accounts are aware of the accounts and the policies and procedures for them.
Review the policy and procedures for use of the Oracle default accounts including direct use of the Oracle SYS and SYSTEM accounts with the IAO and DBA.
If a policy does not exist for their use, this is a Finding.
If procedures, automated or manual, for logging default account use are not defined or implemented, this is a Finding.
If monitoring use of default accounts do not exist or is not implemented, this is a Finding.
V-2511
False
DO0140-ORACLE11
Review the policy and procedures for use of the Oracle default accounts including direct use of the Oracle SYS and SYSTEM accounts with the IAO and DBA.
If a policy does not exist for their use, this is a Finding.
If procedures, automated or manual, for logging default account use are not defined or implemented, this is a Finding.
If monitoring use of default accounts do not exist or is not implemented, this is a Finding.
I
Information Assurance Officer
1367