Why does DBSAT findings not match STIGs?
We are trying to satisfy both DBSAT findings and STIG requirements to satisfy our auditors. I'm curious why a DBSAT finding says one thing, but the associated STIG says something else?
For example there is a DBSAT finding about PASSWORD_LOCK_TIME. It needed a numeric value in order to get a PASS finding result. But STIG V-270549 says that the value needs to be set at UNLIMITED.
We initially had all values at UNLIMITED, then changed it to 1000 based on the DBSAT finding. Then changed it back to UNLIMITED based on the STIG.
So why are they wanting different things. I thought that Oracle was supposed to follow the STIGS?