V-270498
Oracle Database 19c Security Technical Implementation Guide
Title
Oracle Database must associate organization-defined types of security labels having organization-defined security label values with information in storage.
Description
<VulnDiscussion>Without the association of security labels to information, there is no basis for the database management system (DBMS) to make security-related access-control decisions. Security labels are abstractions representing the basic properties or characteristics of an entity (e.g., subjects and objects) with respect to safeguarding information. These labels are typically associated with internal data structures (e.g., tables, rows) within the database and are used to enable the imple...
Fix Text (Documentation Requirement)
Define the policy for security labels defined for the data. Document the security label requirements and configure database security labels in accordance with the policy. To provide reliable security labeling of information in storage, enable DBMS features; deploy third-party software; or add custom data structures, data elements, and application code. Oracle recommends Oracle Label Security. For additional information on Oracle Label Security: https://docs.oracle.com/en/database/oracle/oracle-database/19/olsag/label-security-administrators-guide.pdf.