E-Business Suite Customers Can Now Be More Secure!
By Roxana Bradescu on Feb 11, 2008
Last week we announced the certification of Oracle Database Vault for use with Oracle E-Business Suite. It couldn�t have happened without the hard work our E-Business Suite colleagues. They put out a great post explaining Database Vault so wanted to let them bask in some much deserved glory before posting about this as well.
We talk about the benefits of Database Vault all the time but it really takes considering its use with an application like E-Business Suite to drive home the point. Organizations rely on Oracle E-Business Suite applications to drive key components of their business from finance to human resources to supply chain. E-Business Suite includes applications like Oracle Human Capital Management, Oracle Financial Management and Oracle Customer Relationship Management contain personal identification information (PII), social security numbers, employee salary data, all your customers, credit card numbers, etc.
Today anyone with DBA privileges can look all the application data in the database and pretty much do anything they want to the database objects that manage that data. Think about it: the DBA you hired last week go into the database to find out how much all the other DBAs make, get a list of the company customers and their credit card numbers (his golden parachute), and decide to test his backup script against the production database accidentally dropping the whole thing due to a bug in his script! Not once do we describe this nightmare new DBA without the people in the room calling out names �Oh yeah that was Joe� or �Or yeah that was Phil�.
Using Oracle Database Vault, E-Business Suite customers can protect E-Business Suite data from unauthorized access inside the Oracle database. They can enforce separation of duties within the Oracle database, ensuring that even a DBA cannot access sensitive E-Business Suite application data, as well as defend against intentional or accidental database changes that can harm E-Business Suite application data. Also Database Vault can protect against ad-hoc access to E-Business Suite data based on extensible rules and multiple factors such as IP address, time of day, and application. Using Database Vault, E-Business Suite customers can consolidate application databases and enforce strong boundaries between sensitive business data such as that found in financial and human resource application databases.
To obtain Oracle Database Vault policies for use with Oracle E-Business Suite Release as well as technical information and best practices, please refer to Integrating Oracle E-Business Suite 11i with Oracle Database Vault 10.2.0.3 (Metalink Note 428503.1)