Herunterladen Diese Seite drucken

Checklist According To "Security Measure Plan For Oracle Database 12C - Siemens SICAM CP-8050 Administrator Security-Handbuch

Vorschau ausblenden Andere Handbücher für SICAM CP-8050:

Werbung

Security Measure Plan for Oracle Database
A.1
Checklist according to "Security Measure Plan for
Oracle Database 12c"
(Released by Siemens Cert, 2017-02-28. Version 2.0)
System Name: SICAM TOOLBOX II, 6.01 HF01
Version of checked Database: Oracle 12.1.0.1.160719
Chapter
Measure
No.
3.1
M126797
3.2
M126112
3.3
M126833
3.4
M126580
3.5
M126738
3.6
M126734
4.1
M126140
4.2
M126876
4.3
M126621
4.4
M126360
4.5
M126811
4.6
M126436
5.1
M126351
5.2
M126884
5.3
M126150
5.4
M126954
196
Measure
No.
Secure Underlying Operating System
The database is embedded in TOOLBOXII. The TOOLBOX II policy
according securing of the underlying operating system is to give it's
responsibility in customer's hand.
Perform Secure Installation
Apply Oracle Security Patches
Each new TOOLBOXII release uses the latest Oracle Security
Patch. During TOOLBOXII's lifetime it is possible to
get current Oracle Security Patches by using special TBII Hotfixes.
Secure the Oracle Data Dictionary
Separate Datasets that Belong to Different
Application Domains
All datasets belongs only to TOOLBOXII. There are no other
application domains.
Protect Stored Confidential Data
Database- and TOOLBOX II-Passwords are encrypted. All other
data is classified as not confidential, therefore it is not encrypted.
Disable Execution of Administrative
Commands in TNS Listener
Restrict Access to TNS Listener
By default there is no restriction of network access to TNS Listener.
If required, it can be done by System Administrators.
Disable the use of SSLv3
Set Authentication Timeout
Leave Remote Authentication Disabled
Protect Confidential Network Traffic
Database- and TOOLBOXII-Passwords are encrypted. All other data
is classified as not confidential, therefore it is not encrypted.
Use Secure Logon Version
Change Default Passwords
Disable Unneeded Accounts
Adapt User Profile Password Settings
All settings are done, except limitation of maximum password
lifetime.
Reason: Database only possible client is SICAM TOOLBOX II. It's
database passwords are changed at each SICAM TOOLBOX II
major release.
SICAM A8000 Serie / RTUs / TOOLBOX II / Device Manager
ADMINISTRATOR Security-Handbuch
DC0-114-2.15, Ausgabe 12.2017
Done
No
Yes
Yes *)
Yes **)
Yes
Yes
Yes
No
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Partly

Quicklinks ausblenden:

Werbung

loading