SV-30742r1_rule
V-6767
DBMS security compliance
DG0007-ORACLE11
CAT II
10
Apply available security guidance to the DBMS system.
If DoD security guidance is not available, the following are acceptable in descending order as available:
(1) Commercially accepted practices (e.g., SANS);
(2) Independent testing results (e.g., ICSA); or
(3) Vendor literature
Review security and administration documentation maintained for the DBMS system for indications that security guidance has been applied to the DBMS system.
If DoD security guidance is not available, the following are acceptable in descending order as available:
(1) Commercially accepted practices (e.g., SANS);
(2) Independent testing results (e.g., ICSA); or
(3) Vendor literature
If the DBMS system has not been secured using available security guidance as listed above, this is a Finding.
V-6767
False
DG0007-ORACLE11
Review security and administration documentation maintained for the DBMS system for indications that security guidance has been applied to the DBMS system.
If DoD security guidance is not available, the following are acceptable in descending order as available:
(1) Commercially accepted practices (e.g., SANS);
(2) Independent testing results (e.g., ICSA); or
(3) Vendor literature
If the DBMS system has not been secured using available security guidance as listed above, this is a Finding.
M
Information Assurance Officer
1368