The file normally is in $ORACLE_HOME/dbs and the file name is initsid.ora

Yes it is advised to disable O7_DICTIONARY_ACCESSIBILITY because if it is enabled and you grant DELETE ANY to the user he/she gets privilege on SYS schme also.

Sanjay