Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-15645 | DG0142-ORACLE11 | SV-24805r2_rule | ECAR-3 | Medium |
Description |
---|
The AUDIT_SYS_OPERATIONS parameter is used to enable auditing of actions taken by the user SYS. The SYS user account is a shared account by definition and holds all privileges in the Oracle database. It is the account accessed by users connecting to the database with SYSDBA or SYSOPER privileges. |
STIG | Date |
---|---|
Oracle Database 11g Instance STIG | 2014-04-02 |
Check Text ( C-29371r2_chk ) |
---|
From SQL*Plus: select value from v$parameter where name = 'audit_sys_operations'; If the value returned is FALSE, this is a Finding. |
Fix Text (F-26396r1_fix) |
---|
From SQL*Plus: alter system set audit_sys_operations = TRUE scope = spfile; The above SQL*Plus command will set the parameter to take effect at next system startup. |