Skip to content

II - Mission Support Sensitive

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000516-DB-000363

    Group
  • The Oracle WITH GRANT OPTION privilege must not be granted to non-DBA or non-Application administrator user accounts.

    An account permission to grant privileges within the database is an administrative function. Minimizing the number and privileges of administrative accounts reduces the chances of privileged accoun...
    Rule Medium Severity
  • SRG-APP-000516-DB-000363

    Group
  • Execute permission must be revoked from PUBLIC for restricted Oracle packages.

    Access to the following packages should be restricted to authorized accounts only. UTL_FILE: allows Oracle accounts to read and write files on the host operating system. UTL_SMTP: allows messages ...
    Rule Medium Severity
  • SRG-APP-000516-DB-000363

    Group
  • The Oracle REMOTE_OS_AUTHENT parameter must be set to FALSE.

    Setting this value to TRUE allows operating system authentication over an unsecured connection. Trusting remote operating systems can allow a user to impersonate another operating system user and c...
    Rule High Severity
  • SRG-APP-000516-DB-000363

    Group
  • The Oracle REMOTE_OS_ROLES parameter must be set to FALSE.

    Setting REMOTE_OS_ROLES to TRUE allows operating system groups to control Oracle roles. The default value of FALSE causes roles to be identified and managed by the database. If REMOTE_OS_ROLES is s...
    Rule High Severity
  • SRG-APP-000516-DB-000363

    Group
  • The Oracle SQL92_SECURITY parameter must be set to TRUE.

    The configuration option SQL92_SECURITY specifies whether table-level SELECT privileges are required to execute an update or delete that references table column values. If this option is disabled (...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules