FOLLOW THE PRINCIPLE OF LEAST PRIVILEGE
Oracle recommends you avoid granting powerful privileges to new database users,
even privileged users. The Oracle DBA role should be granted with caution and
only to those privileged user who need full DBA privileges. Special attention
should be given when assigning privileges to application schemas. Access to the
SYSDBA role should be granted with extreme care and only to those who are in
Oracle Database Security Checklist Page 6
the most trusted position. Auditing should be used to monitor all activities of
users connecting with the SYSDBA role or other administrative roles such as the
DBA role, CREATE ANY TABLE privilege and so forth. For optimal auditing
performance set your audit destination to point to the operating system.