1. Home
  2. Security Hardening
  3. DISA STIG Oracle 11 Installation V9R1 Windows
  4. DG0053-ORACLE11 – A single database connection configuration file should not be used to configure all database clients.

DG0053-ORACLE11 – A single database connection configuration file should not be used to configure all database clients.

Details

Many sites distribute a single client database connection configuration file to all site database users that contains network access information for all databases on the site. Such a file provides information to access databases not required by all users that may assist in unauthorized access attempts.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Develop, document and implement procedures to distribute client connection definitions or definition files that contain only connection definitions authorized for that user or user workstation.

Include or note these procedures in the System Security Plan.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles