Call for Oracle support & training (800) 766-1884
Free Oracle Tips

Home
Corporate Oracle Training
Custom Oracle Training
Oracle New Features Training
Advanced Oracle DBA Classes
Oracle Tuning Courses
Oracle Tips & Tricks
Oracle Training Links
Oracle Training Links
Oracle Training Links

We are top for USA Oracle Training Clients

 

Free Oracle Tips


 
HTML Text AOL

Free Oracle App Server Tips


 
HTML Text

Oracle support

Oracle training

Oracle tuning

Rednecks!

Remote Oracle

Custom Oracle Training

 

   
  Oracle Tips by Burleson

Chapter 10 Oracle Grants Auditing

TIMESTAMP USERNAME                       ACTION_NAME
--------- ------------------------------ -----------
OBJ_NAME
----------------------------------------------------
GRANTEE                        PRIV_USED
------------------------------ ---------------------
25-AUG-03 ANANDA                         GRANT ROLE
JUNIOR_CLAIM_VIEWER
NATHAN                         GRANT ANY ROLE

Note the important points here – the ACTION_NAME column shows GRANT ROLE, and the role name is shown in the column OBJ_NAME, as the value JUNIOR_CLAIM_VIEWER. Therefore, the column OBJ_NAME does not show only objects, but grants as well. This is an important fact to remember.

These audit trails clearly show when the privileges were granted or revoked, and by whom. Combining this information with the regular audits, we can identify another important requirement of HIPAA and other security regulations, namely whether the user had any possibility of accessing the data at any point in time. It will also capture any malicious activity in the past. For instance, the user APPUSER is not expected to update the table CLAIMS. However, due to an honest mistake or a deliberate act, the user was granted the privilege for a very short time, during which the user updated some key values, and then the privilege was revoked. A later analysis will reveal that the user does not have update privileges on CLAIMS, so there would be no questioning the possibility of such an act. Although the AUDIT record will show that the update occurred, the analysis
 

The above text is an excerpt from:

Oracle Privacy Security Auditing

The Final Word on Oracle Security

 

This is the only authoritative book on Oracle Security, Oracle Privacy, and Oracle Auditing written by two of the world’s leading Oracle Security experts.

This indispensable book is only

$39.95

 and has an immediate download of working security scripts:

 

http://rampant-books.com/book_2003_2_audit.htm



 
 
 
 

Oracle performance tuning book

 

 

Oracle performance tuning software

 
Oracle performance tuning software
 
Oracle performance Tuning 10g reference poster
 
Oracle training in Linux commands
 
Oracle training Excel
 
 
 
 

 

email BC:


Copyright © 1996 -  2014 by Burleson Inc. All rights reserved.

Oracle® is the registered trademark of Oracle Corporation.