Database Security Products (MOSC)

MOSC Banner

Why does DBSAT findings not match STIGs?

edited Oct 24, 2025 7:20PM in Database Security Products (MOSC) 1 commentQuestion

We are trying to satisfy both DBSAT findings and STIG requirements to satisfy our auditors. I'm curious why a DBSAT finding says one thing, but the associated STIG says something else?

For example there is a DBSAT finding about PASSWORD_LOCK_TIME. It needed a numeric value in order to get a PASS finding result. But STIG V-270549 says that the value needs to be set at UNLIMITED.

We initially had all values at UNLIMITED, then changed it to 1000 based on the DBSAT finding. Then changed it back to UNLIMITED based on the STIG.

So why are they wanting different things. I thought that Oracle was supposed to follow the STIGS?

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center