Oracle Database 12c Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-APP-000516-DB-000363
Group -
Oracle roles granted using the WITH ADMIN OPTION must not be granted to unauthorized accounts.
The WITH ADMIN OPTION allows the grantee to grant a role to another database account. Best security practice restricts the privilege of assigning privileges to authorized personnel. Authorized pers...Rule Medium Severity -
SRG-APP-000516-DB-000363
Group -
Object permissions granted to PUBLIC must be restricted.
Permissions on objects may be granted to the user group PUBLIC. Because every database user is a member of the PUBLIC group, granting object permissions to PUBLIC gives all users in the database ac...Rule Medium Severity -
SRG-APP-000516-DB-000363
Group -
The Oracle Listener must be configured to require administration authentication.
Oracle listener authentication helps prevent unauthorized administration of the Oracle listener. Unauthorized administration of the listener could lead to DoS exploits; loss of connection audit dat...Rule High Severity -
SRG-APP-000516-DB-000363
Group -
Application role permissions must not be assigned to the Oracle PUBLIC role.
Permissions granted to PUBLIC are granted to all users of the database. Custom roles must be used to assign application permissions to functional groups of application users. The installation of Or...Rule Medium Severity -
SRG-APP-000516-DB-000363
Group -
SRG-APP-000516-DB-000363
Group -
Connections by mid-tier web and application systems to the Oracle DBMS from a DMZ or external network must be encrypted.
Multi-tier systems may be configured with the database and connecting middle-tier system located on an internal network, with the database located on an internal network behind a firewall and the m...Rule Medium Severity -
SRG-APP-000516-DB-000363
Group -
Database job/batch queues must be reviewed regularly to detect unauthorized database job submissions.
Unauthorized users may bypass security mechanisms by submitting jobs to job queues managed by the database to be run under a more privileged security context of the database or host system. These q...Rule Medium Severity -
SRG-APP-000516-DB-000363
Group -
SRG-APP-000516-DB-000363
Group -
Sensitive information from production database exports must be modified before import to a development database.
Data export from production databases may include sensitive data. Application developers do not have a need to know to sensitive data. Any access they may have to production data would be considere...Rule Medium Severity -
SRG-APP-000516-DB-000363
Group -
Only authorized system accounts must have the SYSTEM tablespace specified as the default tablespace.
The Oracle SYSTEM tablespace is used by the database to store all DBMS system objects. Other use of the system tablespace may compromise system availability and the effectiveness of host system acc...Rule Medium Severity -
SRG-APP-000516-DB-000363
Group -
SRG-APP-000516-DB-000363
Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.