Oracle Database 11g Installation STIG Version Comparison
Oracle Database 11g Installation STIG
Comparison
There are 1 differences between versions v8 r19 (Jan. 27, 2017) (the "left" version) and v9 r1 (Oct. 27, 2021) (the "right" version).
Check DG7002-ORACLE11 was changed between these two versions. Green, underlined text was added, red, struck-out text was removed.
The regular view of the left check and right check may be easier to read.
Text Differences
Title
A minimum of two Oracle control files must be defined and configured to be stored on separate, archived physical disks (physical or virtual) or archived partitions on a RAID device.
Check Content
From SQL*Plus: select name from v$controlfile; DoD guidance recommends: 1. A minimum of two distinct control files for each Oracle Database Instance. 2. Each control file located on separate, archived physical or virtual storage devices. 3. Different Logical Paths for each control file at the highest level supported by your configuration; for example: UNIX: /ora03/app/oracle/{SID}/control/control01.ctl /ora04/app/oracle/{SID}/control/control02.ctl Windows: D:/oracle/{SID}/control/control01.ctl E:/oracle/{SID}/control/control02.ctl If this minimum is not met, this is a finding. Verify that the mount points or partitions referenced in the file paths indicate separate physical disks. If not, this is a finding. (This includes RAID devices and ASM storage. In the case of SAN storage and where possible, different storage pools must be used for control file locations. This assures ensures not only that different physical disks are used but that separate higher level storage components are used.)
Discussion
Oracle control files are used to store information critical to Oracle database integrity. Oracle uses these files to maintain time synchronization of database files as well as at system startup to verify the validity of system data and log files. Loss of access to the control files can affect database availability, integrity, and recovery.
Fix
Establish at least two Oracle control files. Specify a separate, dedicated disk/directory location for each control file.