1. Home
  2. Security Hardening
  3. DISA STIG Oracle 11 Installation V9R1 Windows
  4. DG0040-ORACLE11 – The DBMS software installation account should be restricted to authorized users – ‘Oracle base directory file permissions are correct’

DG0040-ORACLE11 – The DBMS software installation account should be restricted to authorized users – ‘Oracle base directory file permissions are correct’

Details

DBA and other privileged administrative or application owner accounts are granted privileges that allow actions that can have a greater impact on database security and operation. It is especially important to grant access to privileged accounts to only those persons who are qualified and authorized to use them.

Solution

Develop, document and implement procedures to restrict use of the Oracle DBMS software installation account.

Unix environments:
Ensure that the Oracle DBMS software installation account is disabled when not in use, except in cases where this would interfere with required functionality. In such cases, prevent direct logon as the Oracle DBMS software installation account by locking its password; authorize the appropriate administrative users to operate as the Oracle DBMS software installation account via the ‘su’ or ‘sudo’ command.

Other environments:
Ensure that the Oracle DBMS software installation account is disabled when not in use.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles