Oracle Version: 19C
OS : OL 7.6
I built 3 RAC and 4 standalone databases (all 19c). It is in production now.
My DBA colleague says having a password file is a security risk which might not go well with the auditors.
Lets say I remove password file from these DBs to make auditors happy and then one day I lose oracle and root OS users' passwords, and I need to do an administrative task in the DB, how can I do it ?
Is having password file really a security risk ?