Get a Free Magzine ...Profit:The Executive's Guide to Oracle Applications

Subscribe to the OracleAppsHub to receive notifications when there are new posts:

 get RSS feed
 Get a Free Magzine ...Profit:The Executive's Guide to Oracle Applications

Security : Oracle Audit Vault

Posted on August 15th, 2011 by Sanjit Anand |Print This Post Print This Post |Email This Post Email This Post

Have you tried OracleappsHub in ipad/iphone/smart Phone? Don't wait. try it today

In security series, lets know another product.

Oracle Audit Vault is a security product that automates the consolidation of audit data into a secure repository, enabling efficient monitoring and reporting. This makes Oracle Audit Vault is a powerful solution providing a secure repository, built-in reporting, event alerting.This uses Oracle data security to protect audit data end-to-end. It helps to:

  • Consolidate and secure audit data from multiple instances of these databases – Oracle, Microsoft SQL Server, Sybase, IBM DB2.
  • Oracle Audit Vault is having out-of-the box compliance reports such as SOX, PCI and HIPAA requirements.
  • This also have entitlement reports for Oracle database to showing users, privileges and roles.
  • Policies can be created for SQL statements, schema objects, database privileges like alter, create, drop, grant etc.
  • Oracle Audit Vault raise alerts for suspicious activity on sensitive data like employee salaries, credit card numbers etc.
  • This have feature to capture before/after data value changes from Oracle database transaction logs.
  • Audit Vault can be administered and managed separately through Audit Vault server and Console

Oracle Audit Vault

Functional architecture of Audit Vault consists of two major components :

  • Audit Vault Server – A stand-alone stacked application that contains a data warehouse built on a customized installation of Oracle Database.
  • Audit Vault Collection Agent – The Agent is responsible for managing the collectors, which are specific to an audit source the source database and the Audit Vault Server by pulling the audit trail data from the source and sending it to the Audit Vault Server over SQL*Net.

dgreybarrow Scenarios Lets try to do a fitment of this product . here is one problem.

Customer is having a large set of sensitive data that gets Access or modified frequently but not audited then probably .

Solution: If have similar problem , Implement Oracle Audit Vault. The approach would be:

  • Develop a policy to identify and protect sensitive information.
  • Automate the collection and consolidation of audit data.
  • Quickly and automatically detect unauthorized activities that violate security and governance policies.

dgreybarrow Oracle Note:

Related Posts

Posted in Oracle Application | 2 Comments »Email This Post Email This Post | Print This Post Print This Post

Have you tried OracleappsHub in ipad/iphone/smart Phone? Don't wait. try it today
2 Responses
  1. Alkesh Chavda Says:

    Good article Sanjit,

    We (Ategrity Solutions) love Oracle Audit Vault so much that we have created a managed database auditing service using Oracle Audit Vault as our platform.

    Your scenario is good but the majority of clients can not or do not have the expertise to develop the solutions you have listed – hence why we have developed a service to accommodate this – http://www.ategrity.com/

    Kind regards

    Alkesh

  2. Sanjit Anand Says:

    Thanks Alkesh for sharing .

Leave a Comment

Please note: Comment moderation is enabled and may delay your comment. There is no need to resubmit your comment.