• No results found

Data Security: Strategy and Tactics for Success

N/A
N/A
Protected

Academic year: 2021

Share "Data Security: Strategy and Tactics for Success"

Copied!
27
0
0

Loading.... (view fulltext now)

Full text

(1)

Data Security: Strategy and

Tactics for Success

DatabaseVisions,Inc. Fairfax, Va

Oracle Gold Partner Solution Provider Oracle Security Specialized

(2)

Overview

Cloud Computing presents dynamic

challenges to data architectures. Effective Cloud Governance, Risk, and Compliance in a shared, elastic environment requires a strategic approach:

 data security plan

(3)

Cloud computing

 computing framework in which elastic,

scalable, often virtualized resources are provided as a service over the Internet.

 Users may have no knowledge, expertise, or

(4)

Cloud computing models

NIST describes cloud computing in three service models:

 software as a service (SaaS),

 infrastructure as a services (IaaS)

(5)
(6)
(7)

data security plan

 Provide management guidelines and cost

justification for organization's data lifecycle access controls & information assurance

 When do security breaches occur

 Who is agent of security breach

 What is cost of security breach

(8)

identify sensitive data

 Classify all data elements of enterprise

 Label all data elements of enterprise with

ACCESS CLASSIFICATION

* Personal Identifiable Information, PII * National Numbers, SSN

* Salaries, Financials, Bonuses, PCI * Strategic Intellectual Assets, R&D,

(9)

protect sensitive data

 Use tools to protect sensitive data

* encryption

* fine-grained access privileges * separation of duties

(10)

monitor sensitive data

 Executive dashboard visibility of sensitive

data access, and security controls in effect

 daily, event based reports of sensitive

data access & suspicious access patterns

 monitor sensitive data access real-time

 use predictive adaptive, analytic

(11)

data security tactics

Use Oracle database features, product

options, and 3rd party tools to execute your

strategic data security plan.

 User Management

 Access Controls

 Monitoring

(12)

User management

 Oracle Identity Management, OIM, automates

adding, updating, deleting user account

provisions from directories and applications

 Oracle Enterprise Users, defines user in

directory for application lifecyle throughout the enterprise. OIM infrastructure, an

LDAP-compliant directory service to centrally store and manage users.

(13)

enterprise users: techniques

Two Tiered Architectures: DB & MW Admin ORACLE_BASE/ORACLE_HOME ORACLE_BASE/MW_HOME/WL_HOME[wlsever_10_3] ORACLE_BASE/MW_HOME/oes_coherence ORACLE_BASE/MW_HOME/oracle_common ORACLE_BASE/MW_HOME/user_projects/domains/oes_admin ORACLE_BASE/MW_HOME/oes_client

(14)

Access controls overview

 At all times, “Least Privilege” access

permissions and security policies

 Control row-level security at database table,

view, synonym, column-level

 Prevent unauthorized access from

development and production teams

(15)

Access controls: FGAC

 Virtual Private Database: FGAC

 Create policies, for who can access what

rows by controlling WHERE clause

 Oracle Label Security: VPD + row “column

(16)

Access controls: Multi-Factor

 Multi-Factor Access Controls [MFAC]: who,

what statement, when, where, how data is accessed or audited

 Implemented using Oracle Database Vault, or

(17)

Access controls: SoD

 SEPARATION of DUTIES: Oracle Database

Vault

 Divide privilege user (DBA) access among

several database roles to ensure no user has full control over data and system configuration

 Prevents SYS user (DBA privileged) access

(18)

monitoring

 Oracle Audit Vault, alerts suspicious access

of sensitive data, records ALL SQL

processing of database for compliance in secure repository for audit compliance

 Enterprise Manager Configuration Pack,

collect information about system hardware, operating system, database tier, application tier for compliance and stability

(19)

data protection: mask

 Oracle Data Masking, obfuscates sensitive

information: credit card, social security number, patient, or customer names,

 Data can be replaced with realistic values.

Because Data Masking preserves application integrity, it allows production data to be safely used for non-production purposes

(20)

Data protection: encryption

 Oracle Advanced Security, Transparent Data

Encryption for tablespace or column

 Encryption provides “get out of jail free” pass

in event of data breach, as defined by government regulatory statutes such as California Senate Bill 1386

(21)

Data protection: backup

 Oracle Secure Backup, centralized Tape

Backup System integrated with Oracle

Enterprise Manager and RMAN to encrypt data at rest

 Protect heterogeneous file systems,

NAS,SAN

 25-40% faster than comparable media

(22)

oracle 11g security options

Advanced Security Options Data Masking

Audit Vault Label Security Database Vault Total Recall

OEM Change Management Pack OEM Diagnostics Pack

OEM Tuning Pack Oracle Secure Backup

(23)

Options vs licensed features

Oracle 11g EE Options Oracle 11g Licensed Features

Data Masking PL/SQL, sql string functions, custom repository

Audit Vault Table trigger, PL/SQL, sys_context(), custom repository Label Security Virtual Private Database

Total Recall LogMiner

OEM Tuning Pack Explain plain, PL/SQL, custom repository

Database Vault - MFAC Table trigger, PL/SQL, sys_context(), custom repository Database Vault - SoD No

Advanced Security Options No OEM Change Management

Pack

No

(24)

Oracle security applications

Identity Management Suite:

Oracle Identity Directory Oracle Directory Integration Platform Oracle Virtual Directory Oracle Directory Services Manager Oracle Identify Federation

Identity and Asset Management Suite:

Oracle Identity Management Oracle Adaptive Access Management Oracle Access Management Oracle Identity Navigator

(25)

Enterprise virtualization

Sun Ray Software

Oracle Secure Global Desktop Oracle Virtual Box

(26)

summary

Be STRATEGIC in creating a data security plan and roadmap for your organization.

Be mindful of your organization's BUDGET, use knowledge of Oracle 11g licensed features

and unlicensed “options” to execute

information assurance and governance, risk and compliance obligations

(27)

more [email protected]

DatabaseVisions,Inc. an Oracle Systems Integrator and Reseller is Specialized in Oracle Database Security and frequently provides Deep Dive Consultations with

Federal and Commercial Account Managers to help modernize next-generation data

References

Related documents

Nanjing United Chemical Logistics Co., Ltd (UT) is a professional engaged in the third party logistics enterprises of chemical products, which has provide logistics services to

In a low power factor wattmeter the compensating coil is connected (a) in series with current coil. (b) in parallel with current coil (c) in series with pressure coil (d)

Access entry tool for feta to compare nutrient output data of food codes to estimate population distribution of the questionnaire file will enable future researchers using the

[r]

Oracle Audit Vault and Database Firewall APPS Users AUDIT VAULT Firewall Events Database Firewall AUDIT DATA Operating Systems File Systems Directories Custom Audit Data

Data Masking Advanced Security Label Security Secure Backup Total Recall Audit Vault Configuration Management... Oracle

| Apps Users Advanced Security Data Redaction Data Masking TDE Database Vault Privilege Analysis Database Vault Privileged User Controls|.

These results suggest that the postoperative course of the patients who underwent RS might be milder than after LS in cases in which complications developed, whereas the post-