Skip to content

I - Mission Critical Classified

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000516-DB-000363

    Group
  • The Oracle password file ownership and permissions should be limited and the REMOTE_LOGIN_PASSWORDFILE parameter must be set to EXCLUSIVE or NONE.

    It is critically important to the security of your system that you protect your password file and the environment variables that identify the location of the password file. Any user with access to ...
    Rule Medium Severity
  • SRG-APP-000516-DB-000363

    Group
  • System privileges granted using the WITH ADMIN OPTION must not be granted to unauthorized user accounts.

    The WITH ADMIN OPTION allows the grantee to grant a privilege to another database account. Best security practice restricts the privilege of assigning privileges to authorized personnel. Authorized...
    Rule Medium Severity
  • SRG-APP-000516-DB-000363

    Group
  • System Privileges must not be granted to PUBLIC.

    System privileges can be granted to users and roles and to the user group PUBLIC. All privileges granted to PUBLIC are accessible to every user in the database. Many of these privileges convey cons...
    Rule Medium Severity
  • SRG-APP-000516-DB-000363

    Group
  • Oracle roles granted using the WITH ADMIN OPTION must not be granted to unauthorized accounts.

    The WITH ADMIN OPTION allows the grantee to grant a role to another database account. Best security practice restricts the privilege of assigning privileges to authorized personnel. Authorized pers...
    Rule Medium Severity
  • SRG-APP-000516-DB-000363

    Group
  • Object permissions granted to PUBLIC must be restricted.

    Permissions on objects may be granted to the user group PUBLIC. Because every database user is a member of the PUBLIC group, granting object permissions to PUBLIC gives all users in the database ac...
    Rule Medium Severity
  • SRG-APP-000516-DB-000363

    Group
  • The Oracle Listener must be configured to require administration authentication.

    Oracle listener authentication helps prevent unauthorized administration of the Oracle listener. Unauthorized administration of the listener could lead to DoS exploits; loss of connection audit dat...
    Rule High Severity
  • SRG-APP-000516-DB-000363

    Group
  • Application role permissions must not be assigned to the Oracle PUBLIC role.

    Application roles have been granted to PUBLIC. Permissions granted to PUBLIC are granted to all users of the database. Custom roles should be used to assign application permissions to functional gr...
    Rule Medium Severity
  • SRG-APP-000516-DB-000363

    Group
  • Oracle application administration roles must be disabled if not required and authorized.

    Application administration roles, which are assigned system or elevated application object privileges, should be protected from default activation. Application administration roles are determined b...
    Rule Medium Severity
  • SRG-APP-000516-DB-000363

    Group
  • Connections by mid-tier web and application systems to the Oracle DBMS from a DMZ or external network must be encrypted.

    Multi-tier systems may be configured with the database and connecting middle-tier system located on an internal network, with the database located on an internal network behind a firewall and the m...
    Rule Medium Severity
  • SRG-APP-000516-DB-000363

    Group
  • Database job/batch queues must be reviewed regularly to detect unauthorized database job submissions.

    Unauthorized users may bypass security mechanisms by submitting jobs to job queues managed by the database to be run under a more privileged security context of the database or host system. These q...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules