U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.


Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Oracle 11g Database STIG Version 9 Release 1 Checklist Details (Checklist Revisions)

Supporting Resources:


Target CPE Name
Oracle Database 11g cpe:/a:oracle:database_server:11 (View CVEs)
Oracle Database 11g 11.1 cpe:/a:oracle:database_server:11.1 (View CVEs)
Oracle Database 11g 11.2 cpe:/a:oracle:database_server:11.2 (View CVEs)

Checklist Highlights

Checklist Name:
Oracle 11g Database STIG
Checklist ID:
Version 9 Release 1
Review Status:
Governmental Authority: Defense Information Systems Agency
Original Publication Date:

Checklist Summary:

The Oracle Database Security Readiness Review (SRR) targets conditions that undermine the integrity of security, contribute to inefficient security operations and administration, or may lead to interruption of production operations specific to databases. Additionally, the review ensures the site has properly installed and implemented the database environment and that it is being managed in a way that is secure. This checklist provides instructions for review of Oracle DBMS Server versions 11.1 through 11.2.

Checklist Role:

  • Database Management System

Known Issues:

Not provided.

Target Audience:

Systems Administrators and/or Database Administrators

Target Operational Environment:

  • Managed
  • Specialized Security-Limited Functionality (SSLF)

Testing Information:

Not provided.

Regulatory Compliance:

DOD Directive 8500.1 and DOD Instruction 8500.2 and the Information Assurance (IA) Controls


Not provided.


Not provided.

Product Support:

Not provided.

Point of Contact:



Not provided.


Not provided.

Change History:

Changed status from "Under Review" to "Final" - 03 June 2015
Version 8, Release 1.11 - 25 April 2014
Version 8, Release 1.10 - 24 January 2014
Version 8, Release 1.9 - 26 October 2012
Version 8, Release 1.8 - 27 August 2010
Updated "Point of Contact" - 08 January 2015
Version 8, Release 1.12 - 25 January 2015
Version 8, Release 15 - 28 October 2015
Changed status from "Under Review" to "Final" - 04 December 2015
Version 8, Release 16 - 29 January 2016
3/8/2016 - Promote to Final
4/27/2016 - version 1 release 17
moved to FINAL - 6/7/2016
updated to v8, r18 - 07/22/2016
Updated to FINAL - 09/12/2016
Updated to Version 8 Release 19 - 01/27/2017
Updated to FINAL - 03/08/2017
Updated URL to reflect change to the DISA website - http --> https
Updated URLs - 6/13/19
Updated Resource Title - 6/17/19
sunset per DISA - 10/27/2021


URL Description


Reference URL Description

NIST checklist record last modified on 10/27/2021