U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

CIS Oracle Database 12c Benchmark 3.0.0 Checklist Details (Checklist Revisions)

Supporting Resources:

Target:

Target CPE Name
Oracle Database 12c cpe:/a:oracle:database_server:12c (View CVEs)
Oracle Database 12c Release 2 cpe:/a:oracle:database:12.2.0.1 (View CVEs)

Checklist Highlights

Checklist Name:
CIS Oracle Database 12c Benchmark
Checklist ID:
590
Version:
3.0.0
Type:
Compliance
Review Status:
Final
Authority:
Third Party: Center for Internet Security (CIS)
Original Publication Date:
04/24/2020

Checklist Summary:

This document is intended to address the recommended security settings for Oracle Database 12c. This guide was tested against Oracle Database 12c (versions 12.1.0.2 and 12.2.0.1) installed with and without pluggable database support running on a Windows Server 2012 R2 instance as a stand-alone system and running on an Oracle Linux 7 instance also as a stand-alone system. Future Oracle Database 12c critical patch updates (CPUs) may impact the recommendations included in this document. To obtain the latest version of this guide, please visit http://benchmarks.cisecurity.org. If you have questions, comments, or have identified ways to improve this guide, please write us at feedback@cisecurity.org.

Checklist Role:

  • Database Server

Known Issues:

Not provided.

Target Audience:

This benchmark is intended for system and application administrators, security specialists, auditors, help desk, and platform deployment personnel who plan to develop, deploy, assess, or secure solutions that incorporate Oracle Database 12c on Oracle Linux or Microsoft Windows Server.

Target Operational Environment:

  • Managed

Testing Information:

This guide was tested against Oracle Database 12c (versions 12.1.0.2 and 12.2.0.1) installed with and without pluggable database support running on a Windows Server 2012 R2 instance as a stand-alone system and running on an Oracle Linux 7 instance also as a stand-alone system.

Regulatory Compliance:

Not provided.

Comments/Warnings/Miscellaneous:

Not provided.

Disclaimer:

Please see the below link for our current terms of use: https://www.cisecurity.org/cis-securesuite/cis-securesuite-membership-terms-of-use/

Product Support:

feedback@cisecurity.org

Point of Contact:

feedback@cisecurity.org

Sponsor:

Not provided.

Licensing:

Please see the below link for our current terms of use: https://www.cisecurity.org/cis-securesuite/cis-securesuite-membership-terms-of-use/

Change History:

Updated status from "Under Review" to "Final" - 30 June 2015
Update Licensing.
Updating status from "under review" to "final" - 25 August 2015
changed to FINAL - 5/5/2016
updated to FINAL - 01/31/2017
New Checklist - 9/21/18
update to FINAL - 10/22/18
updated product - 4/29/2020
updated URLs - 2/11/2022

Dependency/Requirements:

URL Description

References:

Reference URL Description

NIST checklist record last modified on 02/11/2022