<Insert Picture Here> Oracle Database Security

Similar documents
Database Centric Information Security. Speaker Name / Title

Private Clouds: Opportunity to Improve Data Security and Lower Costs. InfoTRAMS Fusion Tematyczny, Bazy Danych, Kariera I Prywatny Sprzęt t W Pracy

with Oracle IDM Peter Heintzen, Sen. Mgr. Information Security Oracle

The 10 Principles of Security in Modern Cloud Applications

Oracle Audit Vault. Trust-but-Verify for Enterprise Databases. Tammy Bednar Sr. Principal Product Manager Oracle Database Security

Oracle Security Products and Their Relationship to EBS. Presented By: Christopher Carriero

Oracle Database 12c: Administration Workshop Ed 2 NEW

Managing Oracle Database 12c with Oracle Enterprise Manager 12c

Security Compliance and Data Governance: Dual problems, single solution CON8015

Oracle Database 12c: Administration Workshop Ed 2

Oracle Database 12c: Administration Workshop Ed 2

Copyright 2012, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 12

Oracle Label Security Technical Overview. Jaime Briggs Account Manager Strategic Accounts MSc CS, CCISP, CCSK

Survey of Oracle Database

1 Copyright 2011, Oracle and/or its affiliates. All rights reserved. reserved. Insert Information Protection Policy Classification from Slide 8

Private Cloud Database Consolidation Name, Title

Security Readiness Assessment

IT Service Delivery and Support Week Three. IT Auditing and Cyber Security Fall 2016 Instructor: Liang Yao

Copyright 2011, Oracle and/or its affiliates. All rights reserved.

ISO COMPLIANCE GUIDE. How Rapid7 Can Help You Achieve Compliance with ISO 27002

Welcome to IBM Security Guardium Analyzer!

Data Security and Privacy : Compliance to Stewardship. Jignesh Patel Solution Consultant,Oracle

"Charting the Course... Oracle 18c DBA I (3 Day) Course Summary

SQL Security Whitepaper SECURITY AND COMPLIANCE SOLUTIONS FOR PCI DSS PAYMENT CARD INDUSTRY DATA SECURITY STANDARD

IBM services and technology solutions for supporting GDPR program

Defending Against a Dangerous New World

Focus On: Oracle Database 11g Release 2

Oracle E-Business Suite Certified with Oracle Database Vault Certification Overview

WORKSHARE SECURITY OVERVIEW

McAfee Database Security

Oracle Database 12c: Administration Workshop Duration: 5 Days Method: Instructor-Led

Oracle Database 11g: Security Release 2

Oracle Database Auditing

Oracle Database 12c R2: Administration Workshop Ed 3 NEW

Oracle Database 11g: New Features for Administrators DBA Release 2

Oracle Database Vault and Applications Unlimited Certification Overview

SECURITY & PRIVACY DOCUMENTATION

<Insert Picture Here> Managing Oracle Exadata Database Machine with Oracle Enterprise Manager 11g

University of Pittsburgh Security Assessment Questionnaire (v1.7)

Oracle Database 12c R2: Administration Workshop Ed 3

Oracle Database 11g: Security Release 2

Database Consolidation onto Private Cloud. Piotr Kołodziej, Oracle Polska

Oracle Audit Vault Implementation

SQL Security Whitepaper SECURITY AND COMPLIANCE SOLUTIONS FOR SARBANES OXLEYANDCOBIT

Kenna Platform Security. A technical overview of the comprehensive security measures Kenna uses to protect your data

Sponsored by Oracle. SANS Institute Product Review: Oracle Audit Vault. March A SANS Whitepaper. Written by: Tanya Baccam

Oracle Database Vault

Oracle Database 11g for Experienced 9i Database Administrators

Database access control, activity monitoring and real time protection

Google Cloud & the General Data Protection Regulation (GDPR)

Oracle 12C DBA Online Training. Course Modules of Oracle 12C DBA Online Training: 1 Oracle Database 12c: Introduction to SQL:

Oracle Exadata X7. Uwe Kirchhoff Oracle ACS - Delivery Senior Principal Service Delivery Engineer

Modernize Your Backup and DR Using Actifio in AWS

"Charting the Course... Oracle 18c DBA I (5 Day) Course Summary

Archiving. Services. Optimize the management of information by defining a lifecycle strategy for data. Archiving. ediscovery. Data Loss Prevention

LBI Public Information. Please consider the impact to the environment before printing this.

IBM Spectrum Protect Version Introduction to Data Protection Solutions IBM

IBM Tivoli Storage Manager Version Introduction to Data Protection Solutions IBM

HIPAA Controls. Powered by Auditor Mapping.

Security Information & Policies

Exam 1Z0-061 Oracle Database 12c: SQL Fundamentals

CIS Controls Measures and Metrics for Version 7

DBAs can use Oracle Application Express? Why?

ORACLE 11gR2 DBA. by Mr. Akal Singh ( Oracle Certified Master ) COURSE CONTENT. INTRODUCTION to ORACLE

Vormetric Data Security

Sparta Systems TrackWise Digital Solution

SQL Server Solutions GETTING STARTED WITH. SQL Secure

Securing Data-at-Rest

Oracle Database Security Assessment Tool

Transparent Solutions for Security and Compliance with Oracle Database 11g. An Oracle White Paper September 2008

Data Privacy and Protection GDPR Compliance for Databases

Oracle - Oracle Database 12c R2: Administration Workshop Ed 3

PeopleSoft Finance Access and Security Audit

Oracle Advanced Compression: Reduce Storage, Reduce Costs, Increase Performance Bill Hodak Principal Product Manager

Security and Performance advances with Oracle Big Data SQL

Course: Oracle Database 12c R2: Administration Workshop Ed 3

1 Copyright 2011, Oracle and/or its affiliates. All rights reserved.

Enterprise Manager: Scalable Oracle Management

Oracle Database 12c Administration Workshop

Secure Access & SWIFT Customer Security Controls Framework

Tape Sucks for Long-Term Retention Time to Move to the Cloud. How Cloud is Transforming Legacy Data Strategies

Explore the Oracle 10g database architecture. Install software with the Oracle Universal Installer (OUI)

Understand & Prepare for EU GDPR Requirements

Support for the HIPAA Security Rule

Oracle Database 18c and Autonomous Database

Safe Harbor Statement

Oracle Database Vault with Oracle Database 12c ORACLE WHITE PAPER MAY 2015

Oracle Database: SQL and PL/SQL Fundamentals

TECHNOLOGY: Security Encrypting Tablespaces

An Oracle White Paper May Protecting the Electric Grid in a Dangerous World

Google Identity Services for work

ISO STANDARD IMPLEMENTATION AND TECHNOLOGY CONSOLIDATION

FactoryTalk AssetCentre Overview

IBM SmartCloud Notes Security

MySQL Enterprise Security

Oracle Database Security Assessment Tool (DBSAT) Overview

ORACLE DBA I. Exploring Oracle Database Architecture

SOC-2 Requirement Solution Brief. EventTracker 8815 Centre Park Drive, Columbia MD SOC-2

TRACKVIA SECURITY OVERVIEW

Teradata and Protegrity High-Value Protection for High-Value Data

Transcription:

<Insert Picture Here> Oracle Database Security Ursula Koski Senior Principal Architect ursula.koski@oracle.com

Ursula Koski Senior Principal Architect Senior Principal Architect Oracle User Group Liaison and OUGF Board Member (Finland) Joined Oracle 2007 Working mainly with short term database engagements around the world. High availability and disaster recovery area. Have worked as an Oracle DBA for partners from 1994. Interests Professional: Oracle Database Evangelist, Maximum Availability Architecture and Database Disaster Recovery & Problem solving. Personal: Oracle Databases, all technical gadgets (Geek!), traveling and reading.

Data Security Challenges What to secure? Sensitive Data: Confidential, PII, regulatory Data in packaged and custom applications Secure Life cycle: creation, transit, storage, backup, test, transfer Can we secure it now? Secure using existing systems? Transparent? Loss, Unauthorized access, Separation of Duty Will it meet business requirements? Flexible, Transparent, Compliant? Secures both custom and packaged applications? Will it reduce operational cost? Easy to manage? Performant? 3

Oracle Database Security Defense-in-Depth for Security and Compliance Monitoring Configuration Management Audit Vault Total Recall Access Control Database Vault Label Security Encryption and Masking Advanced Security Secure Backup Data Masking 4

Oracle Database Security Defense-in-Depth for Security and Compliance Encryption and Masking Advanced Security Secure Backup Data Masking 5

Oracle Advanced Security Transparent Data Encryption Disk Backups Exports Application Off-Site Facilities No application changes required Efficient encryption of all application data Built-in key lifecycle management Works with Exadata V2 Smart Scans Works with Oracle Advanced Compression 6

Oracle Advanced Security Network Encryption & Strong Authentication Standard-based encryption for data in transit Strong authentication of users and servers No infrastructure changes required Easy to implement 7

Oracle Secure Backup Integrated Tape or Cloud Backup Management Secure data archival to tape or cloud Easy to administer key management Fastest Oracle Database tape backups Leverage low-cost cloud storage 8

Oracle Data Masking Irreversible De-Identification Production LAST_NAME SSN SALARY AGUILAR 203-33-3234 40,000 BENSON 323-22-2943 60,000 Non-Production LAST_NAME SSN SALARY ANSKEKSL 111 23-1111 40,000 BKJHHEIEDK 222-34-1345 60,000 Remove sensitive data from non-production databases Referential integrity preserved so applications continue to work Extensible template library and policies for automation 9

Oracle Database Security Defense-in-Depth for Security and Compliance Access Control Database Vault Label Security Encryption and Masking Advanced Security Secure Backup Data Masking 10

Oracle Database Vault Separation of Duties & Privileged User Controls Application Procurement HR Finance DBA select * from finance.customers DBA separation of duties Limit powers of privileged users Securely consolidate application data No application changes required Works with Oracle Exadata V2 Database Machine 11

Oracle Database Vault Multi-Factor Access Control Policy Enforcement Procurement HR Application Rebates Protect application data and prevent application by-pass Enforce who, where, when, and how using rules and factors Out-of-the box policies for Oracle applications, customizable 12

Oracle Label Security Data Classification for Access Control Confidential Sensitive Transactions Confidential Report Data Public Reports Sensitive Classify users and data based on business drivers Database enforced row level access control Users classification through Oracle Identity Management Suite Classification labels can be factors in other policies 13

Did you know? Finding User Accounts That Have Default Passwords When you create a database in Oracle Database 11g Release 2 (11.2), most of its default accounts are locked with the passwords expired. To find both locked and unlocked accounts that use default passwords, log onto SQL*Plus using the SYSDBA privilege and then query the DBA_USERS_WITH_DEFPWD data dictionary view. SELECT d.username, u.account_status FROM DBA_USERS_WITH_DEFPWD d, DBA_USERS u WHERE d.username = u.username ORDER BY 2,1; USERNAME ACCOUNT_STATUS ----------------- -------------------------- SCOTT EXPIRED & LOCKED 14

Oracle Database Security Defense-in-Depth for Security and Compliance Monitoring Configuration Management Audit Vault Total Recall Access Control Database Vault Label Security Encryption and Masking Advanced Security Secure Backup Data Masking 15

Oracle Audit Vault Automated Activity Monitoring & Audit Reporting HR Data! Alerts CRM Data ERP Data Audit Data Built-in Reports Custom Reports Databases Policies Auditor Consolidate audit data into secure repository Detect and alert on suspicious activities Out-of-the box compliance reporting Centralized audit policy management 16

Oracle Database Auditing Performance Audit users/tables effectively Oracle Database 11.2 ~250 audit records / second 4 CPU 3.6 GHz, 4GB RAM Linux 2.6.9-34.0.1.0.11.ELsmp Existing CPU Work Load: 50% Audit Location Throughput Degradation Additional CPU Used above 50% OS file 1.39% 1.45% XML format file 1.70% 3.51% XML format file + SQL Text 3.22% 4.56% Database Tables 3.84% 4.55% Database Tables + SQL Text 11.93% 13.95% 17

Oracle Total Recall Secure Change Tracking select salary from emp AS OF TIMESTAMP '02-MAY-09 12.00 AM where emp.title = admin Transparently track data changes Efficient, tamper-resistant storage of archives Real-time access to historical data Enables forensics and error correction 18

Oracle Configuration Management Vulnerability Assessment & Secure Configuration Discover Classify Assess Prioritize Fix Monitor Asset Management Policy Management Vulnerability Management Configuration Management & Audit Analysis & Analytics Database discovery Continuous scanning against best practices Detect and prevent unauthorized configuration changes Change management compliance reports 19

Oracle Database Security Defense-in-Depth for Security and Compliance Monitoring Configuration Management Audit Vault Total Recall Access Control Database Vault Label Security Encryption and Masking Advanced Security Secure Backup Data Masking 20

For More Information search.oracle.com database security oracle.com/database/security 21

Oracle Products Available Online Oracle Store Buy Oracle license and support online today at oracle.com/store

23

24