Concentrika poppy

About us

Audit and security of Oracle

 

About the course

We work on the principle that “if you have done it you will understand it”. Therefore do expect this course to involve you a great deal in discussions, workshops and especially examining the system hands on. By the end of the course you will be familiar with Oracle’s client interface, the SQL*PLUS monitor and with simple SQL queries. You will also have the opportunity to author simple PL/SQL programs – Oracle’s database programming language.
In particular, you will come to understand the language surrounding Oracle and will gain immediate credibility talking to the experts you will inevitably have to work with. Furthermore, by understanding the technology, the technical descriptions of risk will become immediately understood.
This hands-on course is intended for auditors and security specialists who are aware their businesses use Oracle based products, but do not understand the database platform and therefore the risks it may carry. You will learn how Oracle is built and a concept of what the various categories of user do on the database and the risks they carry.
Hands on labs will show you how to scan the system for objects, especially sensitive tables. And to find out who can do what to them. Further more, in this age of web technology, the concept of the known authenticated user accessing parts of your data is passing away. It could be anyone!
The course is suitable for all versions of Oracle up to Oracle 8i(V8.1.7). Many features of Oracle version 9.2.0.1.0 (Oracle 9i database) security are included in the 3 day version of training course. Please note that all delegates will receive the fully up to date 8im and 9i versioned manual.
The level of complexity of progressive releases of Oracle is presenting serious challenges of understanding and management, to auditor, developer and DBA alike. You will find the manual contains areas that are quite deep technically, to assist those wishing to addresses complex issues. Along with plenty of easily accessible techniques for the general auditor who requires a higher level approach.

Who should attend

  • Security specialists
  • Audit managers and planners
  • Auditors
  • Specialist legal professionals
  • IT Project managers from sensitive application areas
  • System owners
  • Security conscious system builders

Duration

Oracle 8i - 2 days
With Oracle 9i specifics included - 3 days
Upgrade your skills from 8i to 9i in a 1 day version of the course.

Please discuss the version of the course you wish to receive with sales, before booking, if you are unsure as to your requirements.

1. Introducing Oracle

The database management system
The Oracle security model

4. User security

User creation issues
Categories of users
Viewing users on the system
Profiles
Roles
Permissions and privileges
Passwords
Maintaining user accounts
Power user accounts - system, sys, internal
Startup and shutdown
Operating system security

7. Authentication in three tier architecture

Three tier architecture
Who is the real user?
Does the middle tier have too much privilege?
Authentication options
Limiting the privilege of the middle tier
Auditing the real user

2. SQL*PLUS

Connecting to ORACLE
Commands available in SQL*PLUS
SQL code – the development life cycle
Configuring the SQL*PLUS monitor environment
The data dictionary

5. Backup and recovery of the database

Strategy and tactics
New features in Oracle 8
Logging

8. Auditing the database

Strategy and tactics
The audit sub-system master switch
Creating the audit trail
Viewing the audit settings
Challenge and output
Managing audit data
laying an audit trail

3. The Oracle system

Log files
Datafiles
Init.ora
Net8 *.ora files
The control file
The external password file
Trace and alert files

6. Application data security – including new auditing features at Oracle 9i

Access methods
User context fine grained access control
Fine grained access security policies
Fine-grained auditing (FGA)
Data accuracy
Oracle 9i – new ways into the database

9. Database triggers

Introduction to triggers
Audit triggers

 

10. Audit workpack

 

 

Courses
schedule
Contact us