sqlnet.ora – ‘log_directory_server parameter settings’ Details The log_directory_server must be set to a valid directory owned by the Oracle account and permissions restricted to read/write...
sqlnet.ora – ‘trace_directory_client parameter settings’ Details The trace_directory_client parameter settings must be set to a valid directory owned by the Oracle account and permissions restricted...
sqlnet.ora – ‘trace_directory_server parameter settings’ Details The trace_directory_server must be set to a valid directory owned by the Oracle account and permissions restricted to read/write...
sqlnet.ora – ‘Verify and set permissions with read permissions for everyone’ Details The sqlnet.ora contains the configuration files for the communication between the user and the server including the level of...
sqlplus – ‘Verify and set permissions’ Details The permissions of the binaries for sqlplus on the server must be restricted to the owner of the Oracle...
tkprof – ‘Remove from system’ – removed Details The tkprof utility must be removed from production environments; it is a powerful tool for an attacker to find...
tkprof – ‘Remove from system’ – secured Details The tkprof utility must be removed from production environments; it is a powerful tool for an attacker to find...
Version/Patches – ‘Ensure the latest version of Oracle software and patches have been applied’ Details Using outdated or unpatched software will put the Oracle database and host system at unnecessary risk and violates security...
Windows Oracle Account – ‘Deny Log on Locally Right’ Details The RSA must have limited access requirements. Level 1, Scorable Supportive Information The following resource is also helpful. https://workbench.cisecurity.org/files/580...
Windows Oracle Account Domain Users Group Membership – ‘Remove the RSA from the Domain Users group’ Details The RSA must have limited access requirements. Granting the RSA domain level privileges negates the purpose of the RSA....