Oracle Database 11g: Security
Starting dates and places
Description
In Oracle Database 11g: Security course students learn how to use Oracle database features to meet the security, privacy and compliance requirements of their organization. The current regulatory environment of the Sarbanes-Oxley Act, HIPAA, the UK Data Protection Act, and others requires better security at the database level. Students learn how to secure their database and how to use the database features that enhance security. The course provides suggested architectures for common problems. This course covers the following security features of the database: auditing, encryption for Payment Card Industry Data Security Standard (PCI DSS) including encryption at the column, tablespace and file…
Frequently asked questions
There are no frequently asked questions yet. If you have any more questions or need help, contact our customer service.
In Oracle Database 11g: Security course students learn how to use Oracle database features to meet the security, privacy and compliance requirements of their organization. The current regulatory environment of the Sarbanes-Oxley Act, HIPAA, the UK Data Protection Act, and others requires better security at the database level. Students learn how to secure their database and how to use the database features that enhance security. The course provides suggested architectures for common problems. This course covers the following security features of the database: auditing, encryption for Payment Card Industry Data Security Standard (PCI DSS) including encryption at the column, tablespace and file levels, virtual private database, label security and enterprise user security. Some of the Oracle Network security topics covered are: securing the listener and restricting connections by IP address.
Learn To:- Identify business security requirements
- Set up security policies
- Implement access control
- Manage user authentication
A Live Virtual Class (LVC) is exclusively for registered students; unregistered individuals may not view an LVC at any time. Registered students must view the class from the country listed in the registration form. Unauthorized recording, copying, or transmission of LVC content may not be made.
Audience
- Security Compliance Professionals
- Database Administrators
- Security Administrators
- Security Compliance Auditors
Course Topics Security Requirements
- Data Security Concerns
- Fundamental Data Security Requirements
- Components for enforcing security
- Security Risks: Internal, External, Sabotage, Recovery
- Principle of Least Privilege
- Defining a Security policy
- Implementing a Security Policy
- Maintaining data integrity
- Controlling data access
- Data Protection
- Database Vault overview
- Audit Vault overview
- Combining Optional Security Features
- Compliance Scanner
- Database Control: Policy Trend
- Database Security Checklist
- Installing only what is required
- Applying Security Patches
- 11g Default security settings
- Enforcing Password Management
- System and Object Privileges
- Restricting the Directories Accessible by the User
- Separation of Responsibilities
- Standard Database Auditing
- Monitoring for Suspicious Activity
- Audit Log Location Options
- Viewing Auditing Results
- Configure Auditing to syslog
- Value-Based Auditing
- Triggers and Autonomous Transactions
- Fine-Grained Auditing (FGA)
- Fine-Grained Auditing Policy
- Triggering Audit Events
- Data Dictionary Views
- Enabling and Disabling an FGA Policy
- FGA Policy Guidelines
- Maintaining the Audit Trail
- User Authentication
- User Identified by a Password
- User Identified Externally
- Protecting Passwords
- Encrypted Database Link Passwords
- Audit with Database Links
- Strong User Authentication
- Single Sign-On
- How to Use Certificates for Authentication
- Configuring SSL
- orapki Utility
- How to Use Kerberos for Authentication
- RADIUS Authentication: Overview
- External Secure Password Store
- Setting up Enterprise User Security
- Oracle Identity Management Infrastructure: Default Deployment
- Oracle Database: Enterprise User Security Architecture
- Authenticating Enterprise Users
- User Migration Utility
- Enterprise-User Auditing
- Security Challenges of Three-Tier Computing
- Common Implementations of Authentication
- Restrict the Privileges of the Middle Tier
- Using Proxy Authentication for Database Users
- Using Proxy Authentication for Enterprise Users
- Revoking Proxy Authentication
- Data Dictionary Views for Proxy Authentication
- Authorization
- Assigning Privileges
- Using Enterprise roles
- Implementing a Secure Application Role
- Application Context Overview
- Implementing a Local Context
- Application Context Accessed Globally
- Guidelines
- Understanding Fine Grain Access Control
- Virtual Private Database
- Implementing VPD Policies
- Manage VPD Policies
- Policy Performance
- Checking for Policies Applied to SQL Statements
- Access Control: Overview
- Discretionary Access Control
- Oracle Label Security
- Comparing Oracle Label Security and the VPD
- Policy Enforcement Options
- Managing levels, groups, compartments
- Administering Labels
- Trusted Stored Package Units
- Performance tips
- Understanding Data Masking
- Identifying Sensitive Data for Masking
- Implementing Data Masking
- Data Masking Impact Report
- Understanding encryption
- Cost of encryption
- Encryption is not Access Control
- Data Encryption Challenges
- Encryption Key Management
- Solutions and examples
- Overview
- The DBMS_CRYPTO Package
- Generate Keys Using RANDOMBYTES
- Using ENCRYPT and DECRYPT
- Enhanced Security Using the Cipher Block Modes
- Hash and Message Authentication Code
- Transparent Data Encryption overview
- Components of Data Encryption
- Using Data Encryption
- Using Hardware Security Modules
- Tablespace Encryption
- RMAN Encrypted Backups
- Oracle Secure Backup Encryption
- Using Transparent Mode Encryption
- Using Password Mode Encryption
- Using Dual Mode Encryption
- Restoring encrypted backups
- Security Checklists Overview
- Client Checklist
- Network Security Checklist
- Restricting Network IP Addresses
- Restricting Open Ports
- Encrypting Network Traffic
- Configure Checksumming
- Oracle Net Services Log Files
- Listener Security Checklist
- Restricting the Privileges of the Listener
- Password Protect the Listener
- Administering the Listener Using TCP/IP with SSL
- Analyzing Listener Log Files
Course Objectives
- Use database security features
- Secure the database and its listener
- Manage users using proxy authentication
- Manage secure application roles
- Implement fine-grain access control
- Implement fine-grain auditing
- Use Transparent Data Encryption
Share your review
Do you have experience with this course? Submit your review and help other people make the right choice. As a thank you for your effort we will donate $1.- to Stichting Edukans.There are no frequently asked questions yet. If you have any more questions or need help, contact our customer service.