欢迎来到天天文库
浏览记录
ID:40406586
大小:445.01 KB
页数:42页
时间:2019-08-01
《Oracle数据库安全》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、ImplementingOracleDatabaseSecurityObjectivesAftercompletingthislesson,youshouldbeabletodothefollowing:DescribeyourDBAresponsibilitiesforsecurityImplementsecuritybyapplyingtheprincipleofleastprivilegeManagedefaultuseraccountsImplementstandardpasswords
2、ecurityfeaturesDescribedatabaseauditingDescribeVirtualPrivateDatabase(VPD)IndustrySecurityRequirementsLegal:Sarbanes-OxleyAct(SOX)HealthInformationPortabilityandAccountabilityAct(HIPAA)CaliforniaBreachLawUKDataProtectionActAuditingSecurityRequirement
3、sFullNotesPageSeparationofResponsibilitiesUserswithDBAprivilegesmustbetrusted.Consider:AbuseoftrustAudittrailsprotectthetrustedposition.DBAresponsibilitiesmustbeshared.Accountsmustneverbeshared.TheDBAandthesystemadministratormustbedifferentpeople.Se
4、parateoperatorandDBAresponsibilities.DatabaseSecurityAsecuresystemensurestheconfidentialityofthedatathatitcontains.Thereareseveralaspectsofsecurity:RestrictingaccesstodataandservicesAuthenticatingusersMonitoringforsuspiciousactivityDatabaseSecurityF
5、ullNotesPagePrincipleofLeastPrivilegeInstallonlyrequiredsoftwareonthemachine.Activateonlyrequiredservicesonthemachine.GiveOSanddatabaseaccesstoonlythoseusersthatrequireaccess.Limitaccesstotherootoradministratoraccount.LimitaccesstotheSYSDBAandSYSOPER
6、accounts.Limitusers’accesstoonlythedatabaseobjectsrequiredtodotheirjobs.REVOKEEXECUTEONUTL_SMTP,UTL_TCP,UTL_HTTP,UTL_FILEFROMPUBLIC;O7_DICTIONARY_ACCESSIBILITY=FALSEREMOTE_OS_AUTHENT=FALSEApplyingthePrincipleofLeastPrivilegeProtectthedatadictionary:
7、RevokeunnecessaryprivilegesfromPUBLIC:Restrictthedirectoriesaccessiblebyusers.Limituserswithadministrativeprivileges.Restrictremotedatabaseauthentication:ApplythePrincipleofLeastPrivilegeFullNotesPageManagingDefaultUserAccountsDBCAexpiresandlocksall
8、accounts,except:SYSSYSTEMSYSMANDBSNMPForamanuallycreateddatabase,lockandexpireanyunusedaccounts.UserPasswordagingandexpirationPasswordcomplexityverificationSettingupprofilesImplementingStandardPasswordSecurityFeaturesPasswordhistoryAccountlockingPas
此文档下载收益归作者所有