SV-24959r2_rule
V-16054
Oracle SEC_PROTOCOL_ERROR_TRACE_ACTION parameter
DO6752-ORACLE11
CAT II
10
Set the value for the sec_protocol_error_trace_action initialization parameter to ALERT or LOG.
TRACE may be appropriate for testing or development, but provides more detail than may be useful.
Consider using ALERT for MAC 1 systems.
From SQL*Plus:
alter system set sec_protocol_error_trace_action = 'ALERT' scope = spfile;
OR
alter system set sec_protocol_error_trace_action = 'LOG' scope = spfile;
The above SQL*Plus command will set the parameter to take effect at next system startup.
From SQL*Plus:
select value from v$parameter where name = 'sec_protocol_error_trace_action';
If the value returned is NONE, this is a Finding.
If the value returned is TRACE, LOG or ALERT, this is Not a Finding.
V-16054
False
DO6752-ORACLE11
From SQL*Plus:
select value from v$parameter where name = 'sec_protocol_error_trace_action';
If the value returned is NONE, this is a Finding.
If the value returned is TRACE, LOG or ALERT, this is Not a Finding.
M
Database Administrator
1368