Session 319:
Security Compliance using
Oracle Enterprise Manager 12c

                       Bobby Curtis, MBA
                       Solution Architect
                       BIAS Corporation
                       April 2013
•    Founded in 2000
             •    Oracle Platinum Partner with 20+ specializations
             •    Distinguished Oracle Leader
                      –  Technology Momentum
                      –  Portal Blazer Award
                      –  Titan Award – Red Stack + HW Momentum
                      –  Excellence in Innovation
             •    Management Team is Ex-Oracle
             •    Location(s): Atlanta, Washington D.C.,
                               Offshore – Hyderabad and Chennai, India
About BIAS




             •    Inc.500 fastest growing private company in the U.S. for the 3rd Time
             •    Voted Best Place to work in Atlanta for 2nd year
Bobby Curtis, MBA
                        •    Douglasville, Georgia (west side of Atlanta)
                        •    Solution Architect, BIAS Corp.
About Presenter


                        •    Implementation Specialist for Core Technologies
                        •    IOUG, ODTUG, & GOUSER
                        •    Using Oracle products since 2001
                        •    Previous Life: Military/Systems Administrator



                  Blog: http://www.dbasolved.com
                  Twitter: @curtisbl294
                  Email: bobby.curtis@biascorp.com
                              curtisbl@gmail.com
§  Compliance	
  
                 §  Customer	
  Story	
  -­‐	
  CCH	
  
                 §  Puzzle	
  Pieces	
  
Session Agenda



                 §  Configura8on	
  
                 §  Addi8onal	
  Informa8on	
  
                 §  Customer	
  Improvements	
  
                 §  Wrap-­‐Up	
  
Compliance
Compliance Management   What	
  is	
  compliance	
  management?	
  

                                              The	
  ability	
  to	
  evaluate	
  the	
  
                                              compliance	
  of	
  targets	
  and	
  
                                              systems	
  as	
  they	
  are	
  related	
  to	
  
                                              best	
  prac8ces	
  for	
  configura8on,	
  
                                              security,	
  and	
  storage.	
  
Compliance Overview   Compliance	
  solu8on	
  consists	
  of:	
  
What	
  do	
  these	
  numbers	
  	
  
                      have	
  to	
  do	
  with	
  security	
  compliance?	
  
Compliance Overview

                                                6	
   	
  	
  	
  	
  	
  	
  	
  Frameworks	
  
                                                 :0	
  
                                               50	
   	
  	
  	
  	
  	
  Standards	
  
                                                 :23	
  
                                                 :115	
  	
  	
  	
  Rules	
  
                                             1827	
  
Customer Story
Who	
  is…	
  
                        •  Leading	
  provider	
  of	
  Tax,	
  Accoun8ng	
  and	
  Audit	
  
                           Informa8on	
  SoUware	
  for	
  professionals	
  
                        •  Subsidiary	
  of	
  Wolters	
  Kluwer	
  Tax	
  &	
  Accoun8ng	
  
Customer Story



                        •  Based	
  in	
  Riverwoods,	
  Ill.,	
  office	
  in	
  Kennesaw,	
  GA.	
  

                        •  Largest	
  customer	
  is	
  Internal	
  Revenue	
  Service	
  (IRS)	
  

                        •  Booth	
  1318	
  
                 	
  
•  Reliable	
  monitoring	
  for	
  3	
  RAC	
  environments	
  

                 •  High	
  security	
  requirements	
  
Customer Story



                 •  Needed	
  to	
  enforce	
  compliance	
  

                 •  Annual	
  audits	
  are	
  8me	
  consuming	
  
Compliance Puzzle Pieces
There	
  are	
  three	
  pieces	
  to	
  the	
  compliance	
  
Puzzle Pieces, oh my…
                        puzzle.	
  	
  They	
  are	
  the	
  building	
  blocks	
  for	
  
                        compliance	
  and	
  are	
  hierarchical	
  structure.	
  

                                 1.  Frameworks	
  
                                 2.  Standards	
  
                                 3.  Rules	
  
                                       ü  Real-­‐Time	
  Facets*	
  
                                       ü  Templates*	
  
Puzzle Pieces : Framework   A	
  compliance	
  framework	
  is	
  a	
  hierarchical	
  structure	
  
                            where	
  any	
  node	
  can	
  be	
  mapped	
  to	
  one	
  or	
  more	
  
                            compliance	
  standards	
  and	
  compliance	
  standard	
  
                            rules.	
  
                                     2	
  Types	
  of	
  Frameworks:	
  
                                     	
  

                                     §  Oracle	
  Provided	
  
                                            §  Payment	
  Card	
  Industry	
  (PCI)	
  
                                            §  Generic	
  
                                     §  User-­‐Defined	
  
                                            §  Defined	
  to	
  sa8sfy	
  the	
  needs	
  of	
  your	
  organiza8on	
  
Puzzle Pieces : Standards   A	
  compliance	
  standard	
  is	
  a	
  collec8on	
  of	
  checks	
  or	
  
                            rules.	
  

                                 Standards-­‐Hierarchical	
  Structure:	
  
                                 	
  

                                 §  Compliance	
  Rules	
  
                                 §  Rule	
  Folders	
  
                                      §  Hierarchical	
  structure	
  the	
  constrains	
  compliance	
  rules	
  
                                 §  Compliance	
  Standards	
  
                                        §  Can	
  include	
  other	
  compliance	
  standards	
  
What	
  do	
  standards	
  do:	
  
Puzzle Pieces : Standards
                            	
  

                            §  Represent	
  Industry-­‐wide	
  standards,	
  per	
  target	
  
                            §  Used	
  as	
  reference	
  configura8on/cer8fied	
  configura8on	
  
                            §  Describe	
  best	
  prac8ces	
  for	
  enterprise	
  
                                                                               Security	
  Compliance	
  Standards	
  By	
  
                                                                                             Target	
  Type	
  
                                                                        Automa8c	
  Storage	
  Management	
  (ASM)	
      2	
  
                                                                        Cluster	
                                         1	
  
                                                                        Cluster	
  Database	
                             7	
  
                                                                        Database	
  Instance	
                            9	
  
                                                                        Host	
                                            2	
  
                                                                        Listener	
                                        2	
  
                                                                        Total	
                                          23	
  
A	
  compliance	
  rule	
  is	
  a	
  test	
  that	
  determines	
  if	
  
                        configura8on	
  data	
  change	
  affects	
  compliance.	
  	
  
                        Based	
  on	
  the	
  result,	
  the	
  compliance	
  score	
  is	
  
Puzzle Pieces : Rules

                        calculated.	
  
                                   3	
  Types	
  of	
  Rules:	
  
                                   §  Repository	
  Rules	
  
                                         §  Check	
  against	
  metrics	
  in	
  management	
  repository	
  
                                   §  Weblogic	
  Server	
  Signature	
  Rules	
  
                                         §  Describe	
  poten8al	
  problems	
  based	
  on	
  info	
  about	
  Weblogic	
  
                                             Server	
  and	
  environment	
  
                                   §  Real-­‐Time	
  Monitoring	
  
                                         §  Monitors	
  ac8ons	
  performed	
  by	
  users	
  on	
  targets	
  
Puzzle Pieces : Templates   Enable	
  security	
  compliance;	
  templates	
  have	
  to	
  be	
  
                            enabled.	
  
Evaluation…Understand
                                                       Number	
  of	
  targets	
  
                                                       evaluated	
  as	
  Cri8cal,	
  
                                                       Warning,	
  or	
  Compliant	
     Average	
  Score	
  for	
  Evalua8on	
  




                        Number	
  of	
  Cri8cal,	
                                              Compliance	
  Score	
  Ra9ngs	
  
                        Warning,	
  or	
  Minor	
  Warning	
                                 Cri9cal	
                        <	
  60	
  
                        viola8ons	
  across	
  all	
  targets	
                             Warning	
                         <	
  80	
  

                                                                                           Compliant	
                        >	
  80	
  	
  
Compliance	
  Summary	
  &	
  Details	
  
                     	
  

                            §  Enterprise	
  Summary	
  
Evaluation… Review

                            §  Compliance	
  Dashboard	
  
Configure the Puzzle Pieces
Configure: Library




                     3	
     2	
     1	
     N/A	
  
Configure: Rules
Configure: Rules
Configure: Standards
Compliance	
  Standards	
  are:	
  
                       	
  

                       §  Hierarchical	
  in	
  nature	
  
                       §  Must	
  have	
  at	
  least	
  1	
  rule	
  
Configure: Standards

                       	
  

                              Adding	
  Rules/Standards	
  is	
  
                              simple!	
  
                              	
  

                                     Right	
  click-­‐>Edit-­‐>Add	
  
Configure: Framework



                       §  Top	
  most	
  level	
  of	
  compliance	
  
                       §  Only	
  standards	
  can	
  be	
  added	
  
                       §  Standards	
  in	
  subgroups	
  
§  Oracle	
  Security	
  Template	
  
          §  Immediately	
  available	
  
              (some	
  delay)	
  
Results
Results
Dashboard	
  Consists	
  of:	
  
          	
  

          §  Compliance	
  Framework	
  
              Summary	
  
          §  Compliance	
  Summary	
  
          §  Least	
  Compliant	
  Generic	
  
              Systems	
  
Results




          §  Most	
  Recently	
  Discovered	
  
              Unmanaged	
  Hosts	
  
          §  Least	
  Compliant	
  Targets	
  
Additional Information
Compliance	
  from	
  the	
  command	
  line:	
  
                §    export_compliance_group	
  
                §    export_compliance_standard_rule	
  	
  
                §    export_standard	
  	
  	
  	
  	
  	
  	
  
                §    import_compliance_object	
  	
  	
  
EMCLI Options
Views	
  for	
  Compliance	
  (SYSMAN)	
  
                         §    MGMT$COMPLIANCE_STANDARD_GROUP	
  
                         §    MGMT$COMPLIANCE_STANDARD	
  
                         §    MGMT$COMPLIANCE_STANDARD_RULE	
  
                         §    MGMT$COMPLIANCE_SUMMARY	
  
SQL Options



                         §    MGMT$COMPLIANT_TARGETS	
  
                         §    MGMT$COMPLIANCE_TREND	
  
                         §    MGMT$COMPOSITE_CS_EVAL_SUMMARY	
  
              Oracle	
  Enterprise	
  Manager	
  Cloud	
  Control	
  Extensibility	
  Programmers	
  Guide	
  
              Chapter	
  18	
  	
  	
  
To	
  use	
  compliance	
  standards:	
  
                                             §    CREATE_COMPLIANCE_ENTITY	
  
Privileges & Roles

                                             §    FULL_ANY_COMPLIANCE_ENTITY	
  
                                             §    VIEW_ANY_COMPLIANCE_FWK	
  
                                             §    MANAGE_TARGET_COMPLIANCE	
  
                                             §    VIEW	
  
                                             §    EM_COMPLIANCE_DESIGNER	
  (ROLE)	
  
                                             §    EM_COMPLIANCE_OFFICE	
  (ROLE)	
  
Customer Story.. Improvement?
§  Able	
  to	
  monitor	
  in	
  all	
  environments	
  
                 §  Has	
  a	
  easier	
  and	
  measurable	
  way	
  of	
  enforcing	
  
                     compliance	
  across	
  environments	
  
Customer Story


                 	
  

                 §  Expected	
  to	
  reduce	
  annual	
  audit	
  8mes	
  by	
  
                     40%-­‐50%	
  
§  Brief	
  customer	
  story	
  
          §  Talked	
  about	
  compliance	
  and	
  its	
  importance	
  
          §  Implemented	
  security	
  aspects	
  of	
  the	
  compliance	
  
              model	
  and	
  how	
  to	
  review	
  results	
  
          §  Discussed	
  addi8onal	
  op8ons	
  for	
  compliance	
  
Wrap Up




          §  Results	
  of	
  customer	
  implemen8ng	
  compliance	
  
Discussion & Questions
Thank You for Attending

    Blog: http://www.dbasolved.com
    Twitter: @curtisbl294
    Email: bobby.curtis@biascorp.com
                curtisbl@gmail.com




      hrp://www.biascorp.com	
  
      	
  

More Related Content

PPTX
GoldenGate CDR from UKOUG 2017
PPTX
Hit Refresh with Oracle GoldenGate Microservices
PPTX
OOW19 - HOL5221
PPTX
Database As A Service: OEM + ODA (OOW 15 Presentation)
PPTX
Extreme Replication - Performance Tuning Oracle GoldenGate
PPTX
Oracle GoldenGate Performance Tuning
PDF
Deep Dive into Automating Oracle GoldenGate Using the New Microservices
PDF
IOUG Data Integration SIG w/ Oracle GoldenGate Solutions and Configuration
GoldenGate CDR from UKOUG 2017
Hit Refresh with Oracle GoldenGate Microservices
OOW19 - HOL5221
Database As A Service: OEM + ODA (OOW 15 Presentation)
Extreme Replication - Performance Tuning Oracle GoldenGate
Oracle GoldenGate Performance Tuning
Deep Dive into Automating Oracle GoldenGate Using the New Microservices
IOUG Data Integration SIG w/ Oracle GoldenGate Solutions and Configuration

What's hot (20)

PDF
Oracle GoldenGate 12c CDR Presentation for ECO
PPTX
Enable GoldenGate Monitoring with OEM 12c/JAgent
PDF
Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...
PPTX
Understanding Oracle GoldenGate 12c
PDF
Oracle Database 19c - poslední z rodiny 12.2 a co přináší nového
PPTX
Oracle GoldenGate and Baseball - 5 Keys for Moving to the Cloud
PPTX
OEM12c, DB12c and You! - RMOUG TD2014 Edition
PPTX
What’s New in Oracle Database 19c - Part 1
PPTX
Improve PostgreSQL replication with Oracle GoldenGate
PPTX
ECO 2022 - OCI and HashiCorp Terraform
PDF
Zero Downtime Migration
PDF
Oracle ZDM KamaleshRamasamy Sangam2020
PDF
Spotlight private dns-oraclecloudservices
PPTX
Oracle GoldenGate 18c - REST API Examples
PDF
Oracle Fleet Patching and Provisioning Deep Dive Webcast Slides
PDF
Maa goldengate-rac-2007111
DOC
Oracle dba
PDF
New availability features in oracle rac 12c release 2 anair ss
PDF
Oracle RAC 19c: Best Practices and Secret Internals
PPTX
Oracle Goldengate training by Vipin Mishra
Oracle GoldenGate 12c CDR Presentation for ECO
Enable GoldenGate Monitoring with OEM 12c/JAgent
Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...
Understanding Oracle GoldenGate 12c
Oracle Database 19c - poslední z rodiny 12.2 a co přináší nového
Oracle GoldenGate and Baseball - 5 Keys for Moving to the Cloud
OEM12c, DB12c and You! - RMOUG TD2014 Edition
What’s New in Oracle Database 19c - Part 1
Improve PostgreSQL replication with Oracle GoldenGate
ECO 2022 - OCI and HashiCorp Terraform
Zero Downtime Migration
Oracle ZDM KamaleshRamasamy Sangam2020
Spotlight private dns-oraclecloudservices
Oracle GoldenGate 18c - REST API Examples
Oracle Fleet Patching and Provisioning Deep Dive Webcast Slides
Maa goldengate-rac-2007111
Oracle dba
New availability features in oracle rac 12c release 2 anair ss
Oracle RAC 19c: Best Practices and Secret Internals
Oracle Goldengate training by Vipin Mishra
Ad

Viewers also liked (12)

DOC
Jazz chant
PDF
WAMIN0119 - MM Mar 2015 (002)
PDF
最新oeko证书
PPTX
Unidad 1 introducción
PDF
ольга ринк презентация
PDF
Elihouri logo f
PDF
Protecting Patient Privacy
PPTX
PDF
Audizione FIRE al senato sui certificati bianchi
Jazz chant
WAMIN0119 - MM Mar 2015 (002)
最新oeko证书
Unidad 1 introducción
ольга ринк презентация
Elihouri logo f
Protecting Patient Privacy
Audizione FIRE al senato sui certificati bianchi
Ad

Similar to Session 319 (20)

PPT
European Business Rules Conference 2005 : Rule Standards
PDF
DSS ITSEC Conference 2012 - RISK & COMPLIANCE
PDF
Конфигурация и соответствие: две половины единого целого.
PDF
Semantic Enterprise Architecture
PDF
Higher education IAM-seminar Turku 10.12.2009
PDF
Workware systems company presentation web aug 11
PDF
Legislative Compliance Management Solution (LCMS)
ODP
Zen and Enterprise Architecture
PPTX
Alberto lagna soa that works
PDF
Enable 2 Pager
PDF
Requirements & scope
PDF
Bringing Agility and Flexibility to Data Design and Integration
PDF
Lean & agile 101 for Astute Entrepreneurs
PDF
Making Scrum Stick Inside Heavy Regulated Industries (2012)
PDF
How to implement interoperability
PDF
Methodology
PPTX
Kahn.theodore
PPTX
Selecting and Implementing Insurance Advertising Compliance Technology Solutions
PDF
PDF
Are Agile And Secure Development Mutually Exclusive?
European Business Rules Conference 2005 : Rule Standards
DSS ITSEC Conference 2012 - RISK & COMPLIANCE
Конфигурация и соответствие: две половины единого целого.
Semantic Enterprise Architecture
Higher education IAM-seminar Turku 10.12.2009
Workware systems company presentation web aug 11
Legislative Compliance Management Solution (LCMS)
Zen and Enterprise Architecture
Alberto lagna soa that works
Enable 2 Pager
Requirements & scope
Bringing Agility and Flexibility to Data Design and Integration
Lean & agile 101 for Astute Entrepreneurs
Making Scrum Stick Inside Heavy Regulated Industries (2012)
How to implement interoperability
Methodology
Kahn.theodore
Selecting and Implementing Insurance Advertising Compliance Technology Solutions
Are Agile And Secure Development Mutually Exclusive?

More from Bobby Curtis (17)

PPTX
Leverage Restful APIs in Oracle GoldenGate
PPTX
RheoData_OGG-Classic2Microservices_2024-UKOUG24.pptx
PPTX
RheoData_23ai_Vector-Datatype-Webinar-2024.pptx
PPTX
MySQLHeatwave-TheBasics.pptx
PPTX
Oracle GoldenGate 21c New Features and Best Practices
PPTX
Terraform & Oracle Cloud Infrastructure
PPTX
Oracle GoldenGate on Docker
PDF
Oracle GoldenGate Studio Intro
PDF
5 Keys to Oracle GoldenGate Implemenations
PPTX
Extreme replication at IOUG Collaborate 15
PPTX
Examining Oracle GoldenGate Trail Files
PPTX
Exachk and oem12c - IOUG C15LV
PDF
Extreme Replication - RMOUG Presentation
PDF
Oracle virtualbox basic to rac attack
PDF
How many ways to monitor oracle golden gate - OOW14
PDF
Exachk and oem12c
PDF
Oracle GoldenGate Presentation from OTN Virtual Technology Summit - 7/9/14 (PDF)
Leverage Restful APIs in Oracle GoldenGate
RheoData_OGG-Classic2Microservices_2024-UKOUG24.pptx
RheoData_23ai_Vector-Datatype-Webinar-2024.pptx
MySQLHeatwave-TheBasics.pptx
Oracle GoldenGate 21c New Features and Best Practices
Terraform & Oracle Cloud Infrastructure
Oracle GoldenGate on Docker
Oracle GoldenGate Studio Intro
5 Keys to Oracle GoldenGate Implemenations
Extreme replication at IOUG Collaborate 15
Examining Oracle GoldenGate Trail Files
Exachk and oem12c - IOUG C15LV
Extreme Replication - RMOUG Presentation
Oracle virtualbox basic to rac attack
How many ways to monitor oracle golden gate - OOW14
Exachk and oem12c
Oracle GoldenGate Presentation from OTN Virtual Technology Summit - 7/9/14 (PDF)

Recently uploaded (20)

PDF
STKI Israel Market Study 2025 version august
PDF
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
PDF
sustainability-14-14877-v2.pddhzftheheeeee
PPTX
Custom Battery Pack Design Considerations for Performance and Safety
PDF
Convolutional neural network based encoder-decoder for efficient real-time ob...
PDF
Produktkatalog für HOBO Datenlogger, Wetterstationen, Sensoren, Software und ...
PPT
What is a Computer? Input Devices /output devices
PPTX
MicrosoftCybserSecurityReferenceArchitecture-April-2025.pptx
PDF
Abstractive summarization using multilingual text-to-text transfer transforme...
PDF
The influence of sentiment analysis in enhancing early warning system model f...
PDF
A Late Bloomer's Guide to GenAI: Ethics, Bias, and Effective Prompting - Boha...
PDF
Zenith AI: Advanced Artificial Intelligence
PPTX
Chapter 5: Probability Theory and Statistics
PPT
Geologic Time for studying geology for geologist
PDF
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
PDF
A contest of sentiment analysis: k-nearest neighbor versus neural network
PDF
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
PDF
Hindi spoken digit analysis for native and non-native speakers
PPTX
Microsoft Excel 365/2024 Beginner's training
PDF
A proposed approach for plagiarism detection in Myanmar Unicode text
STKI Israel Market Study 2025 version august
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
sustainability-14-14877-v2.pddhzftheheeeee
Custom Battery Pack Design Considerations for Performance and Safety
Convolutional neural network based encoder-decoder for efficient real-time ob...
Produktkatalog für HOBO Datenlogger, Wetterstationen, Sensoren, Software und ...
What is a Computer? Input Devices /output devices
MicrosoftCybserSecurityReferenceArchitecture-April-2025.pptx
Abstractive summarization using multilingual text-to-text transfer transforme...
The influence of sentiment analysis in enhancing early warning system model f...
A Late Bloomer's Guide to GenAI: Ethics, Bias, and Effective Prompting - Boha...
Zenith AI: Advanced Artificial Intelligence
Chapter 5: Probability Theory and Statistics
Geologic Time for studying geology for geologist
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
A contest of sentiment analysis: k-nearest neighbor versus neural network
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
Hindi spoken digit analysis for native and non-native speakers
Microsoft Excel 365/2024 Beginner's training
A proposed approach for plagiarism detection in Myanmar Unicode text

Session 319

  • 1. Session 319: Security Compliance using Oracle Enterprise Manager 12c Bobby Curtis, MBA Solution Architect BIAS Corporation April 2013
  • 2. •  Founded in 2000 •  Oracle Platinum Partner with 20+ specializations •  Distinguished Oracle Leader –  Technology Momentum –  Portal Blazer Award –  Titan Award – Red Stack + HW Momentum –  Excellence in Innovation •  Management Team is Ex-Oracle •  Location(s): Atlanta, Washington D.C., Offshore – Hyderabad and Chennai, India About BIAS •  Inc.500 fastest growing private company in the U.S. for the 3rd Time •  Voted Best Place to work in Atlanta for 2nd year
  • 3. Bobby Curtis, MBA •  Douglasville, Georgia (west side of Atlanta) •  Solution Architect, BIAS Corp. About Presenter •  Implementation Specialist for Core Technologies •  IOUG, ODTUG, & GOUSER •  Using Oracle products since 2001 •  Previous Life: Military/Systems Administrator Blog: http://www.dbasolved.com Twitter: @curtisbl294 Email: bobby.curtis@biascorp.com curtisbl@gmail.com
  • 4. §  Compliance   §  Customer  Story  -­‐  CCH   §  Puzzle  Pieces   Session Agenda §  Configura8on   §  Addi8onal  Informa8on   §  Customer  Improvements   §  Wrap-­‐Up  
  • 6. Compliance Management What  is  compliance  management?   The  ability  to  evaluate  the   compliance  of  targets  and   systems  as  they  are  related  to   best  prac8ces  for  configura8on,   security,  and  storage.  
  • 7. Compliance Overview Compliance  solu8on  consists  of:  
  • 8. What  do  these  numbers     have  to  do  with  security  compliance?   Compliance Overview 6                Frameworks   :0   50            Standards   :23   :115        Rules   1827  
  • 10. Who  is…   •  Leading  provider  of  Tax,  Accoun8ng  and  Audit   Informa8on  SoUware  for  professionals   •  Subsidiary  of  Wolters  Kluwer  Tax  &  Accoun8ng   Customer Story •  Based  in  Riverwoods,  Ill.,  office  in  Kennesaw,  GA.   •  Largest  customer  is  Internal  Revenue  Service  (IRS)   •  Booth  1318    
  • 11. •  Reliable  monitoring  for  3  RAC  environments   •  High  security  requirements   Customer Story •  Needed  to  enforce  compliance   •  Annual  audits  are  8me  consuming  
  • 13. There  are  three  pieces  to  the  compliance   Puzzle Pieces, oh my… puzzle.    They  are  the  building  blocks  for   compliance  and  are  hierarchical  structure.   1.  Frameworks   2.  Standards   3.  Rules   ü  Real-­‐Time  Facets*   ü  Templates*  
  • 14. Puzzle Pieces : Framework A  compliance  framework  is  a  hierarchical  structure   where  any  node  can  be  mapped  to  one  or  more   compliance  standards  and  compliance  standard   rules.   2  Types  of  Frameworks:     §  Oracle  Provided   §  Payment  Card  Industry  (PCI)   §  Generic   §  User-­‐Defined   §  Defined  to  sa8sfy  the  needs  of  your  organiza8on  
  • 15. Puzzle Pieces : Standards A  compliance  standard  is  a  collec8on  of  checks  or   rules.   Standards-­‐Hierarchical  Structure:     §  Compliance  Rules   §  Rule  Folders   §  Hierarchical  structure  the  constrains  compliance  rules   §  Compliance  Standards   §  Can  include  other  compliance  standards  
  • 16. What  do  standards  do:   Puzzle Pieces : Standards   §  Represent  Industry-­‐wide  standards,  per  target   §  Used  as  reference  configura8on/cer8fied  configura8on   §  Describe  best  prac8ces  for  enterprise   Security  Compliance  Standards  By   Target  Type   Automa8c  Storage  Management  (ASM)   2   Cluster   1   Cluster  Database   7   Database  Instance   9   Host   2   Listener   2   Total   23  
  • 17. A  compliance  rule  is  a  test  that  determines  if   configura8on  data  change  affects  compliance.     Based  on  the  result,  the  compliance  score  is   Puzzle Pieces : Rules calculated.   3  Types  of  Rules:   §  Repository  Rules   §  Check  against  metrics  in  management  repository   §  Weblogic  Server  Signature  Rules   §  Describe  poten8al  problems  based  on  info  about  Weblogic   Server  and  environment   §  Real-­‐Time  Monitoring   §  Monitors  ac8ons  performed  by  users  on  targets  
  • 18. Puzzle Pieces : Templates Enable  security  compliance;  templates  have  to  be   enabled.  
  • 19. Evaluation…Understand Number  of  targets   evaluated  as  Cri8cal,   Warning,  or  Compliant   Average  Score  for  Evalua8on   Number  of  Cri8cal,   Compliance  Score  Ra9ngs   Warning,  or  Minor  Warning   Cri9cal   <  60   viola8ons  across  all  targets   Warning   <  80   Compliant   >  80    
  • 20. Compliance  Summary  &  Details     §  Enterprise  Summary   Evaluation… Review §  Compliance  Dashboard  
  • 22. Configure: Library 3   2   1   N/A  
  • 26. Compliance  Standards  are:     §  Hierarchical  in  nature   §  Must  have  at  least  1  rule   Configure: Standards   Adding  Rules/Standards  is   simple!     Right  click-­‐>Edit-­‐>Add  
  • 27. Configure: Framework §  Top  most  level  of  compliance   §  Only  standards  can  be  added   §  Standards  in  subgroups  
  • 28. §  Oracle  Security  Template   §  Immediately  available   (some  delay)   Results
  • 30. Dashboard  Consists  of:     §  Compliance  Framework   Summary   §  Compliance  Summary   §  Least  Compliant  Generic   Systems   Results §  Most  Recently  Discovered   Unmanaged  Hosts   §  Least  Compliant  Targets  
  • 32. Compliance  from  the  command  line:   §  export_compliance_group   §  export_compliance_standard_rule     §  export_standard               §  import_compliance_object       EMCLI Options
  • 33. Views  for  Compliance  (SYSMAN)   §  MGMT$COMPLIANCE_STANDARD_GROUP   §  MGMT$COMPLIANCE_STANDARD   §  MGMT$COMPLIANCE_STANDARD_RULE   §  MGMT$COMPLIANCE_SUMMARY   SQL Options §  MGMT$COMPLIANT_TARGETS   §  MGMT$COMPLIANCE_TREND   §  MGMT$COMPOSITE_CS_EVAL_SUMMARY   Oracle  Enterprise  Manager  Cloud  Control  Extensibility  Programmers  Guide   Chapter  18      
  • 34. To  use  compliance  standards:   §  CREATE_COMPLIANCE_ENTITY   Privileges & Roles §  FULL_ANY_COMPLIANCE_ENTITY   §  VIEW_ANY_COMPLIANCE_FWK   §  MANAGE_TARGET_COMPLIANCE   §  VIEW   §  EM_COMPLIANCE_DESIGNER  (ROLE)   §  EM_COMPLIANCE_OFFICE  (ROLE)  
  • 36. §  Able  to  monitor  in  all  environments   §  Has  a  easier  and  measurable  way  of  enforcing   compliance  across  environments   Customer Story   §  Expected  to  reduce  annual  audit  8mes  by   40%-­‐50%  
  • 37. §  Brief  customer  story   §  Talked  about  compliance  and  its  importance   §  Implemented  security  aspects  of  the  compliance   model  and  how  to  review  results   §  Discussed  addi8onal  op8ons  for  compliance   Wrap Up §  Results  of  customer  implemen8ng  compliance  
  • 39. Thank You for Attending Blog: http://www.dbasolved.com Twitter: @curtisbl294 Email: bobby.curtis@biascorp.com curtisbl@gmail.com hrp://www.biascorp.com