Oracle Audit

Páginas: 2 (437 palabras) Publicado: 13 de julio de 2012
Oracle Audit Checklist
1. Consider host identification and authentication mechanisms 2. Consider host resource access control to protect the Oracle programs, and databases 3. Consider use ofoperating system audit trail mechanisms 4. Identify the Oracle products and versions in use. 5. Identify the major applications which are using the Oracle Database Server. 6. Obtain Oracle initializationfile (init.ora) and review security options 7. Obtain listing of v$parameter and ensure consistent with init.ora 8. Obtain the following Data Dictionary Views: DBA_USERS (database users), DBA_ROLES(database roles that have been defined), DBA_ROLE_PRIVS (relationship of users to roles), ROLE_ROLE_PRIVS (relationship of roles to roles), DBA_SYS_PRIVS (system privileges associated with roles & users),DBA_PROFILES (Resource Limits and Password Controls) 9. Review DBA_USERS and ensure that all users are valid. 10. Consider default and generic user-ids. 11. Ensure default passwords for DBA users (sysand system) have been changed. 12. Review init.ora and determine use of OPS$, OS_AUTHENT prefix 13. Determine use of REMOTE_OS_AUTHENT 14. Determine whether the system privileges granted to each userare appropriate. 15. Determine mechanisms available within client applications for password quality as well as password changes and frequency. 16. Identify database objects (tables and views) fromDBA_OBJECTS, and determine system and application tables which should be reviewed. 17. For database objects subject to audit, review the level of access granted to the object and ensure that objectprivileges are appropriate. 18. Consider the appropriateness of granting access to object privileges with the ADMIN OPTION, (review DBA_TAB_PRIVS). 19. Review INIT.ORA to determine if auditing has beenturned on (AUDIT_TRAIL parameter is set to NONE; DBA or SA). 20. Determine the level of system auditing (DBA_STMT_AUDIT_OPTS) 21. Determine the level of object auditing (DBA_OBJ_AUDIT_OPTS) 22....
Leer documento completo

Regístrate para leer el documento completo.

Estos documentos también te pueden resultar útiles

  • ORACLE
  • Oracle
  • Oracle
  • oracle
  • Oracle
  • Oracle
  • oracle
  • ORACLE

Conviértase en miembro formal de Buenas Tareas

INSCRÍBETE - ES GRATIS