I - Mission Critical Sensitive
Rules and Groups employed by this XCCDF Profile
-
SRG-APP-000516-DB-000363
<GroupDescription></GroupDescription>Group -
Access to default accounts used to support replication must be restricted to authorized DBAs.
<VulnDiscussion>Replication database accounts are used for database connections between databases. Replication requires the configuration of ...Rule Medium Severity -
SRG-APP-000516-DB-000363
<GroupDescription></GroupDescription>Group -
Oracle instance names must not contain Oracle version numbers.
<VulnDiscussion>Service names may be discovered by unauthenticated users. If the service name includes version numbers or other database prod...Rule Medium Severity -
SRG-APP-000516-DB-000363
<GroupDescription></GroupDescription>Group -
Fixed user and public database links must be authorized for use.
<VulnDiscussion>Database links define connections that may be used by the local database to access remote Oracle databases. These links provi...Rule Medium Severity -
SRG-APP-000516-DB-000363
<GroupDescription></GroupDescription>Group -
A minimum of two Oracle control files must be defined and configured to be stored on separate, archived disks (physical or virtual) or archived partitions on a RAID device.
<VulnDiscussion>Oracle control files are used to store information critical to Oracle database integrity. Oracle uses these files to maintain...Rule Low Severity -
SRG-APP-000516-DB-000363
<GroupDescription></GroupDescription>Group -
A minimum of two Oracle redo log groups/files must be defined and configured to be stored on separate, archived physical disks or archived directories on a RAID device.
<VulnDiscussion>The Oracle redo log files store the detailed information on changes made to the database. This information is critical to dat...Rule Medium Severity -
SRG-APP-000516-DB-000363
<GroupDescription></GroupDescription>Group -
The Oracle WITH GRANT OPTION privilege must not be granted to non-DBA or non-Application administrator user accounts.
<VulnDiscussion>An account permission to grant privileges within the database is an administrative function. Minimizing the number and privil...Rule Medium Severity -
SRG-APP-000516-DB-000363
<GroupDescription></GroupDescription>Group -
Execute permission must be revoked from PUBLIC for restricted Oracle packages.
<VulnDiscussion>Access to the following packages should be restricted to authorized accounts only. UTL_FILE: allows Oracle accounts to read ...Rule Medium Severity -
SRG-APP-000516-DB-000363
<GroupDescription></GroupDescription>Group -
The Oracle REMOTE_OS_AUTHENT parameter must be set to FALSE.
<VulnDiscussion>Setting this value to TRUE allows operating system authentication over an unsecured connection. Trusting remote operating sys...Rule High Severity -
SRG-APP-000516-DB-000363
<GroupDescription></GroupDescription>Group -
The Oracle REMOTE_OS_ROLES parameter must be set to FALSE.
<VulnDiscussion>Setting REMOTE_OS_ROLES to TRUE allows operating system groups to control Oracle roles. The default value of FALSE causes rol...Rule High Severity -
SRG-APP-000516-DB-000363
<GroupDescription></GroupDescription>Group -
The Oracle SQL92_SECURITY parameter must be set to TRUE.
<VulnDiscussion>The configuration option SQL92_SECURITY specifies whether table-level SELECT privileges are required to execute an update or ...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.