II - Mission Support Classified
Rules and Groups employed by this XCCDF Profile
-
SRG-APP-000516-DB-000363
<GroupDescription></GroupDescription>Group -
The Oracle WITH GRANT OPTION privilege must not be granted to non-DBA or non-Application administrator user accounts.
<VulnDiscussion>An account permission to grant privileges within the database is an administrative function. Minimizing the number and privil...Rule Medium Severity -
SRG-APP-000516-DB-000363
<GroupDescription></GroupDescription>Group -
The Oracle REMOTE_OS_AUTHENT parameter must be set to FALSE.
<VulnDiscussion>Setting this value to TRUE allows operating system authentication over an unsecured connection. Trusting remote operating sys...Rule High Severity -
SRG-APP-000516-DB-000363
<GroupDescription></GroupDescription>Group -
The Oracle REMOTE_OS_ROLES parameter must be set to FALSE.
<VulnDiscussion>Setting REMOTE_OS_ROLES to TRUE allows operating system groups to control Oracle roles. The default value of FALSE causes rol...Rule High Severity -
SRG-APP-000516-DB-000363
<GroupDescription></GroupDescription>Group -
The Oracle SQL92_SECURITY parameter must be set to TRUE.
<VulnDiscussion>The configuration option SQL92_SECURITY specifies whether table-level SELECT privileges are required to execute an update or ...Rule Medium Severity -
SRG-APP-000516-DB-000363
<GroupDescription></GroupDescription>Group -
The Oracle password file ownership and permissions should be limited and the REMOTE_LOGIN_PASSWORDFILE parameter must be set to EXCLUSIVE or NONE.
<VulnDiscussion>It is critically important to the security of your system that you protect your password file and the environment variables t...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.