Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-15627 | DG0117-ORACLE11 | SV-24422r1_rule | ECPA-1 | Medium |
Description |
---|
Privileges granted outside the role of the administrative user job function are more likely to go unmanaged or without oversight for authorization. Maintenance of privileges using roles defined for discrete job functions offers improved oversight of administrative user privilege assignments and helps to protect against unauthorized privilege assignment. |
STIG | Date |
---|---|
Oracle 11 Database Instance STIG | 2014-01-14 |
Check Text ( None ) |
---|
None |
Fix Text (F-3786r1_fix) |
---|
Revoke assigned administrative privileges from database accounts and assign to accounts via roles. Document roles and assignments in the System Security Plan. |