X

Cloud Security Perspectives and Insights

Recent Posts

Database Security

How much Database Security is Enough? Know where to start

We often talk about the Maximum Security Architecture (MSA), but the reality is that not every database needs that level of protection. I thought it might be worth spending some time on what a baseline security posture for the Oracle Database should include – what the Minimal Security Architecture should be. Once we know the maximum and minimum, then we can think of database security on a sliding scale, with your database’s security controls adjusted to reflect the value of the data contained within the database, and your organization’s willingness to accept risk to that data.                   We like to see these seven simple things that can be done for ANY Oracle database, including Oracle Standard Edition, without any additional-cost licenses.  Adjust your configuration to remove unnecessary risk Apply security patches in a timely manner Practice good password discipline Reduce account privileges wherever possible Know your data Audit security-relevant activity Encrypt database network traffic These seven baseline security practices form the foundation for follow-on security controls that increase the security posture (and decrease risk) all the way up to the Maximum Security Architecture. Without them, adding additional technical controls may improve security, but it will not result in a truly secure system.  Adjust your configuration to remove unnecessary risk. There are hundreds of database parameters, and many of those impact the security posture for the system. Oracle provides the Database Security Assessment Tool (DBSAT) to help you evaluate your configuration and identify settings that may introduce additional risk. DBSAT is simple to download and run, usually producing usable reports within minutes.  If you are running databases in the Oracle Cloud, you can also use Oracle Data Safe (included with your Database as a Service subscription) to perform the same types of checks DBSAT does for on-premises databases. Apply security patches in a timely manner. Oracle releases security patches quarterly. With each release, we also provide guidance on the type of vulnerabilities being mitigated in the patch, the attack vector/complexity, and the severity. The reality is that once we release a patch, it isn’t long before malicious actors begin reverse engineering the patches to learn more about vulnerabilities and how they can be exploited. In some cases, the gap between our release of a patch and the availability of automated exploits can be as little as a few days. As every experienced IT professional knows, patching carries its own operational risk, and it’s always a balancing act between testing patches and applying them quickly. The important thing is to evaluate each patch and make a decision on your timeline for applying the patch. The decades-old DBA mantra of “if it ain’t broke, don’t fix it” doesn’t match up with modern risk evaluation! If you are not already subscribed to receive notifications of new critical patches, you can do so here. Practice good password discipline. This sounds so very basic that you may think it doesn’t need to be said, but having evaluated hundreds of production databases in real customer environments I can tell you that it IS something you should be paying attention to. The temptation to create accounts with passwords that don’t expire, and without those annoying complexity  requirements or limits of failed logins seems to draw people in. Remember that most database breaches involve compromised account credentials, and don’t neglect this most basic of security checks. DBSAT (or Oracle Data Safe if your database is in the Oracle Cloud) will help you here, letting you know which users have non-expiring passwords, passwords without complexity checks, and accounts that don’t automatically lock after a certain number of failed logins. Reduce account privileges whenever possible. Most database breaches involved compromised account credentials (sound familiar?). That means that you want to reduce the damage a compromised account can do whenever possible. This can be something as simple as reporting on the privileges/roles an account has and doing a manual review. If you are running the Enterprise Edition of Oracle Database you can use the Privilege Analysis feature to report on privileges an account uses, as well as privileges an account has that are not being used. Those unused privileges are excellent candidates for elimination. It’s always good to be cautious before removing privileges from a user, so I’ll usually take a two-step approach, running privilege analysis for a few months to identify unused privileges and then auditing the use of those privileges for several more months just to be sure the user doesn’t just use them infrequently. Know your data. Many have said that “data is the new oil” – but all data is not created equally. Some data has a higher value (with attendant higher security risk) than other data. Know what types of sensitive data your database holds, and almost as important, how much of that sensitive data there is. DBSAT can help here, with its sensitive data discovery module.  If you are running databases in the Oracle Cloud, you can also use Oracle Data Safe’s sensitive data discovery module.  The baseline security posture we’re discussing here is appropriate for databases with very low risk, databases that don’t contain a lot of sensitive data. The more sensitive data, and the more value that data holds, the more you should be doing to protect it. The baseline security posture we’re discussing here is appropriate for databases with very low risk, databases that don’t contain a lot of sensitive data. The more sensitive data, and the more value that data holds, the more you should be doing to protect it. Audit security-relevant activity. Just as important as knowing the types and quantity of sensitive data in your database is knowing how that data and your database are being accessed. The Oracle Database has superb auditing capabilities, and we improve them with every release. You should be auditing database login events, changes to user accounts, grants of database privileges, and changes to database schema. You may hear “I can’t enable auditing, the performance impact is too high” – but if you think about the things I’m saying to audit you’ll see that these are low frequency, high value operations. They shouldn’t be happening often in most databases, and therefore the performance impact will be minimal. Without an audit trail, your ability to detect malicious activity is severely compromised, and your ability to support a forensic investigation is almost non-existent. Encrypt database network traffic. Encryption of data in motion is standard now - websites that don't use HTTPS are the exception, not the rule. The same should be true for databases. Enabling encryption in an Oracle Database is as simple as a single line in a configuration file that will enable Oracle Native Network Encryption (NNE).  These seven simple steps establish a reasonable security baseline and are the foundation you can build on as you increase your security posture towards the Maximum Security Architecture. If you’d like to learn more about Oracle Database Security, please take a look at our third edition of “Securing your Database – A Technical Primer”.    

We often talk about the Maximum Security Architecture (MSA), but the reality is that not every database needs that level of protection. I thought it might be worth spending some time on what a...

Cloud Infrastructure Security

Why I Love Working with Data Safe and Oracle Database 20c

One of the great things about providing a cloud service is how easy it is to update the service with new features, and Oracle Data Safe is no exception. For example, this week we've added support for Oracle Database 20c. Since we released the service at OpenWorld San Francisco last year, we’ve seen enormous growth and the customer response has been fantastic. If you are running a database in the Oracle Cloud and aren’t already using Data Safe, you really should try it out – Data Safe is included with all of our in-cloud Database as a Service offerings – including Autonomous Database and Exadata Cloud Service – at no additional cost. But, back to my main topic – the ease of updating a cloud service. Comparing the process for enhancing a product or fixing product issues for a cloud service like Data Safe with the same process for an on-premises product is like night and day. For on-premises products, enhancements are scheduled and rolled into a delivery vehicle – usually quarterly or, if it’s a major enhancement, the upcoming annual release. Depending on where in the development cycle the enhancement request comes in, It can take months or even years to bring a new feature to our customers. And the QA cycles before release are long and complex because Oracle is run in so many different server/operating system environments With Data Safe, we roll out fixes and updates every few weeks – it’s a continuous cycle of improvement. Usually these are small improvements – make something easier to understand, fix a typo in some text on screen, add a new sensitive data format to the over 125 existing formats, or a new masking format capability like group-based masking – we are constantly moving the usability and quality of the service higher. Every now and then, it’s a “hot fix” – we spot an issue that is impacting multiple customers and that needs to jump the normal development sprint cycle. In one recent case a report came in about how we were handling large objects from one customer, was confirmed by another customer about eight hours later, and was fixed – with the fix rolled into production for ALL Data Safe customers – less than a day later. This is what I love about cloud services – how quickly we can fix or improve things, and how confident we can be rolling those changes out since the deployment environment is homogenous and controlled. Some recent examples– Automated registration for Autonomous Databases.  I love the Autonomous Database because it lets me get down to business quickly – I don’t have to worry about setting up encryption, separation of duties, patching – the everyday tedium of securing a database. It’s all done for me. But, because it’s all done for me, setting up monitoring tools like Data Safe used to mean I had to figure out what someone else had done for that automation so I could connect my tools into the system. We had several customers who commented on the difficulty of registering an Autonomous Database with Data Safe, so we created the “Easy Button” – the registration is now automated, with network ingress rules, certificate import, credentialing all handled in the background. And we’re working with the Autonomous Database product managers to make things even easier in upcoming releases. But the point is, this great automation that really made a significant difference in the ease of use for Data Safe happened in just a couple of weeks from identifying the issue. And for our customers, that “Easy Button” just appeared on their Autonomous Database console. Federated Logon support. Our initial release of Data Safe required local accounts. During our testing and limited availability program this didn’t seem like a significant barrier to adoption -but once we had Data Safe generally available we received feedback from several customers that they preferred to only use federated identities, no local logins. Here again, in a few short weeks we had the solution developed, tested, and pushed out to our customers. So one day, the requirement for local logins just went away. Private IP address support. Another project we are working on is removing the requirement for a public IP address. The OCI networking team partnered with us on this to create a new network construct called the “Private Endpoint” that allows our customers to grant direct access to Data Safe without having to route that access through a public IP address.  Limited availability for this has been in progress for a few weeks, and so far everyone loves it. One day soon, our customers will just see this new capability appear for them to use with no need for them to apply a patch, install software, upgrade their hardware. Or, our most recent change – Oracle Database 20c (preview edition on Oracle Cloud released this week). With Data Safe, we are able to support Database 20c on the same day it is released! It just doesn’t get much better than this.

One of the great things about providing a cloud service is how easy it is to update the service with new features, and Oracle Data Safe is no exception. For example, this week we've added support for...

Database Security

Silent Disco? Not Quite, but Looks Like it at OpenWorld

If you’re in San Francisco at OpenWorld and stopped by Moscone South - Esplanade Ballroom, you may have thought you joined a silent disco.  No, nobody was dancing to silent music through those multi-colored headsets.  Instead, OpenWorld San Francisco appears to have embraced a new trend in conferences, with open-air presentation rooms and attendees listening to the sessions via headsets. I’m looking forward to our session on Wednesday, when I have the honor to present with Bill Kleyman from Switch, Simon Pane from Pythian, and Hamid Habet from Allianz to present about Oracle Autonomous Database security.  There have been some great announcements already from Larry Ellison and our latest press release.  Join us in our session as we unpack more about the announcements, the latest security updates to Autonomous Database security and hear directly from Allianz and Pythian about their experiences with Data Safe today!  And, if we’re lucky, maybe we’ll have some disco music too.  See you Wednesday at the session: Mitigating Risk with Oracle Autonomous Database [PRO4944] Wednesday, September 18, 04:45 PM - 05:30 PM Moscone South (Esplanade Ballroom) –   156C

If you’re in San Francisco at OpenWorld and stopped by Moscone South - Esplanade Ballroom, you may have thought you joined a silent disco.  No, nobody was dancing to silent music through those...

News

Oracle OpenWorld 19 Daily Report - Tuesday

Hello OpenWorld attendees! I'm writing from the field of Oracle Park with a front row view of Mission: Impossible Fallout! What an exciting event enjoying movie snacks and good company. I hope everyone had an exciting start to OpenWorld and perhaps a few of you reading this were out watching the movie with me. Don't forget to join FitFest.19 this morning to work off the pretzels and popcorn! Tuesday is full of exciting sessions you won't want to miss, but first, I wanted to point out a few of the key announcements and sessions from today! With so much going on at OpenWorld, we know it isn't possible to catch every session, so visit us here each morning for a little recap of the night before and a few key to dos for the day. A few recaps from the day: Announcing Oracle Data Safe Today was an exciting day for Oracle Database Security, the week kicked off with several sessions including Vipin Samar's session, Database Security in 2019: The Innovation Rate Accelerates where Vipin shared that data breaches are up 54% in 2019. Attacks are more pervasive than ever and over 107 countries have now implemented data privacy laws. Oracle is happy to announce Oracle Data Safe.Product Manager, Bettina Schaeumer gave us a first look at Data Safe and there is more to come. Join the Oracle Database team for their Hands-on Labs to get a first look at product hands on and join Michael Mesaros, Director, Database Security Product Management, on Thursday from 9am-9:45am in Moscone South (Espalande Ballroom) Room 155B. The session, Oracle Data Safe: Securing Databases in Oracle Cloud, covers the exciting new cloud service, which provides you with a single pane of glass to assess configuration risk and evaluate database users. We Learned That Security Can Be an Enabler to the Cloud Vice President of Product Marketing for Security, Fred Kost, sat down with a panel of customers and security professionals to hear their perspectives on moving to the cloud securely. It was a great conversation covering what it takes for organizations to move to the cloud, including getting key stakeholders to buy in, considering your compliance needs early, and dreaming big about the possibilities you have in the cloud. The participants in the panel suggested the importance of understanding the shared responsibility model, setting expectations with your cloud provider, and understand your compliance needs across your multi cloud environment. Oracle Cloud Infrastructure Gen2: Stronger Than Ever "It isn't about whether the cloud is secure….it's about how securely you are using it" Laurent Gil, Product Strategy Architect for OCI Development,. A variety of sessions covered the great work customers have been doing with the Oracle Cloud Infrastructure, as innovations continue to be made in industries around the world, Oracle continues to invest money and resources in the best and brightest personnel for the Oracle Cloud Infrastructure. Access our blog covering some of the new announcements for OCI and Oracle Security's press release. Don't miss for Tuesday: Oracle Cloud: A Path and Platform Tuesday,11:15am-12:00pm | YBCA Theater Cloud technologies are beginning to reshape how we think about and interact with the world around us. The opportunities that the cloud presents are real and present today, and they are providing the building blocks for companies to pioneer groundbreaking innovations and disrupt entire industries. Today, we’re seeing emerging technologies and automation permeate every aspect of work and life. The real opportunity of these technologies—which include AI, machine learning, IoT, blockchain, containers and serverless, and human interfaces—is to embrace these technologies on a scale we’ve never before. In this session learn how Oracle Cloud drives new innovation and real change for customers. Securing Business Critical Cloud Workloads: Threats, Implications, and Outcomes Tuesday, 3:15pm - 4pm | Moscone South - Room 209 The next security threat may be something that we have not yet imagined or even considered as a possibility. Beyond attacks against corporations and elections, what other threats exist from nation states, rogue actors, cybercriminals, and others that may threaten our institutions, economy, or way of living? In this session learn about the next security threat and how the direction of technology and the adoption of cloud computing, AI/ML, and other technologies might aid both defenders and attackers. Get a look from the perspective of cloud security and see what’s needed from cloud platforms and security services to protect business-critical workloads and applications as they migrate to cloud platforms. Looking forward to seeing you there! 

Hello OpenWorld attendees! I'm writing from the field of Oracle Park with a front row view of Mission: Impossible Fallout! What an exciting event enjoying movie snacks and good company. I hope...

News

Oracle OpenWorld 2019 Daily Report - Monday

If you are joining us at Oracle OpenWorld today, start your week off with some of these must see sessions and activities! Each day this week, we will publish a morning report of exciting news and recaps from the previous day. To start things off, I'd like to point out a few exciting sessions that we recommend. Be sure to grab your morning coffee and enjoy the sessions!  Cloud Adoption:Getting Everyone On Board Securely  Monday, 09:00 AM - 09:45 AM | Moscone South (Esplanade Ballroom) - Room 156C Migrating applications, data, or workloads to the cloud is not usually a solitary decision, and doing it securely can definitively become a team sport. In this session examine real-world successes and failures with cloud migration from the perspectives of several different enterprise stakeholders. Learn best practices and see how the security conversation can progress in terms that all parties can understand and allow them to pursue their individual objectives and ensure a successful cloud deployment. Hear speakers from not only different functional roles, but at different stages in a cloud journey. Their shared experiences and insights can help you plan and execute a safe and smooth migration of workloads to the cloud. Database Security in 2019: The Innovation Rate Accelerates  Monday, 12:15 PM - 01:00 PM | Moscone South - Room 211 Database security is job #1 in today’s age of data breaches. Join this session to discuss the latest attacks and hear how innovations in Oracle Database security can help protect databases against adversaries. Learn about Oracle Data Safe, a new data security cloud service, and new updated releases of Oracle Key Vault, Oracle Database Security Assessment Tool, and Oracle Audit Vault and Database Firewall. See top security innovations in recent and upcoming database releases. Don’t leave Oracle OpenWorld without learning about the latest security innovations. Read more here in our recent blog.  Oracle Data Safe: Securing Databases in the Oracle Cloud  Monday, 01:45 PM - 02:05 PM | The Exchange (Moscone South) - Theater 3 Join Michael Mesaros, Director, Database Security Product Management, in a session to learn more about this exciting new cloud service. Oracle Data Safe gives you a single pane of glass to assess configuration risk, evaluate database users, manage audit settings, report on database activity, discover sensitive data, and remove sensitive data from non-production copies of the database. Oracle Cloud End-to-End Security: An Overview of Gen2 Protections  Monday, 2:45 PM - 03:30 PM | Moscone South (Esplanade Ballroom) - Room 152A Oracle Cloud Infrastructure is a showcase of Gen2 cloud architecture. This is most evident in the security implications of this evolved design, which is highly differentiated in the market. In this session gain insight to the protections built in to Oracle Cloud Infrastructure and learn about the security operations and applications used in daily defense. Learn about the architecture, its elements, and how they are deployed for tighter tenant isolation, reduced cross-host risk, and greater defense in depth than what is available in legacy clouds. Keynote: Gen2 Cloud-- Autonomous Infrastructure  Monday, 03:45 PM - 05:30 PM | Moscone North - Hall F Join Larry Ellison, Chairman of the Board and Chief Technology Officer, for the Openworld 2019 opening keynote.  If you are looking for even more security related sessions, you are in luck, there are 89 security related sessions at this year's OpenWorld. We have opportunities for customers to try out new products in our hands on labs and hear from customers in a number of panel sessions as well. We look forward to a great start to OpenWorld this year!   

If you are joining us at Oracle OpenWorld today, start your week off with some of these must see sessions and activities! Each day this week, we will publish a morning report of exciting news and...

News

Oracle OpenWorld 2019 is Here! Top 5 Things You Won't Want to Miss

On the night before OpenWorld officially begins, there is a great energy building around the Moscone center. Visitors have been flying in from across the globe and San Francisco has its usual buzzing charm. As we gear up to begin the week, take a look at the top five activities you won't want to miss at this year's Openworld. Welcome and enjoy! 1) Hear real stories from real customers Openworld provides customers the opportunity to hear about the latest product releases, updates to functionality, and most importantly- understand what businesses like them are doing to improve their organizations with Oracle technology. This year there are a variety of customers from every industry and many different countries here to share their stories of success, roadblocks they've experienced along the way, and what's next for them. Take a look at the Openworld session catalog and be sure to stop by a customer panel to catch these real stories. 2) Learn by doing with Hands-on Labs There are so many sessions to choose from each year, but for some, the best way to learn is by doing. The hands-on lab sessions give you a unique experience to try out a product with the experts who helped build it in the same room! Take a moment to join one of our Database Security Hands-on labs sessions and search up additional topics that interests you. 3) Stay connected with social media OpenWorld can often be a whirlwind week, filled with hundreds of sessions, keynotes, and social activities. Stay grounded with the latest updates on our Twitter account @OracleSecurity. We will be live tweeting key security sessions, alerting you on any changes, and unveiling very exciting release information. Also, be sure to check the Oracle Cloud Security Blog each morning as we post insights throughout the week and beyond OpenWorld. Be sure to take plenty of photos and to use #OOW19, we look forward to connecting! 4) Must see sessions Some of the top security sessions include topics surrounding new features and products as well as thought leadership and customer panels. With 89 security related sessions this year, you can't go wrong, but you can't see everything! Security is big this year, don't miss out. 5) Take some time to relax and socialize All work and no play is no fun! Be sure to mix in a few events during your time here in San Francisco. This year, OpenWorld has kicked it up a notch and is providing a lot of relaxation activities for attendees. Oracle Park will be home to several of these activities, including a movie night on Monday, FitFest.19 which offers attendees the chance to sweat it out on their field at Oracle Park in a yoga or bootcamp style class, or make a new furry friend at the "Paws and Relax" experience located in the Exchange. And of course, don’t forget to bring your dancing shoes for CloudFest.19 featuring John Mayer with Flo Rida. You can learn more about most of these events at the Oracle Park Be Well Hub around the corner from the Moscone South entrance on 3rd. Street. Or here at the event highlights page.  Whether this is your first experience at OpenWorld or you've been coming for years, there is sure to be a week full of exciting experiences, announcements, and networking. Don't forget to stay tuned for more content throughout the week and most importantly, have a great time!

On the night before OpenWorld officially begins, there is a great energy building around the Moscone center. Visitors have been flying in from across the globe and San Francisco has its usual buzzing...