The DBMS must provide a report generation capability for audit reduction data.
From Oracle Database 11.2g Security Technical Implementation Guide
Part of SRG-APP-000114-DB-000054
Associated with:
CCI-000157
SV-66429r1_rule
The DBMS must provide a report generation capability for audit reduction data.
Vulnerability discussion
In support of Audit Review, Analysis, and Reporting requirements, audit reduction is a technique used to reduce the volume of audit records in order to facilitate a manual review. Before a security review is conducted, information systems and/or applications with an audit reduction capability may remove many audit records known to have little security significance. This is generally accomplished by removing records generated by specified classes of events, such as records generated by nightly backups. In order to identify and report on what (repetitive) data has been removed via the use of audit reduction, the application must provide a capability to generate reports containing what values were removed by the audit reduction. Audit reduction does not alter original audit records. An audit reduction capability provides support for near real-time audit review and analysis based on policy-based requirements and after-the-fact investigations of security incidents. Reporting tools employing audit reduction methods must not alter the original audit data. An example of a tool employing audit reduction methods is the Windows Event Viewer tool which is used to view and analyze audit logs on Windows systems.The lack of reporting tools for audit reduction can require the DBA, or others responsible for reviewing audit logs, to sort through large amounts of data in order to find relevant records. This can cause important audit records to be missed.
Check content
Verify that audit reduction capabilities are in place for the Oracle audit tables. Since Oracle has no reduction capability per se, a third-party tool or in-house-developed software must be in place to provide this functionality. This must include the ability to report on the excluded audit data.
If this capability has not been implemented, this is a finding.
Fix text
Deploy software capable of performing audit table reduction and of reporting on the excluded audit data.
Pro Tips
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer