Skip Headers
Oracle® Health Sciences Empirica Signal Secure Configuration Guide
Release 8.0
E50112-01
  Go To Table Of Contents
Contents

Previous
Previous
 
Next
Next
 

1 Security overview

The Empirica Signal application is a web application that provides a data mining environment for detecting signals, uncovering patterns, and recognizing trends in adverse event report data. Using the Empirica Signal application, industry and pharmacovigilance professionals can efficiently manage the review, processing, and response to drug and vaccine safety signals.

When your organization implements the Empirica Signal application, it is critical to install the software and its system components using secure installation methods to protect the integrity and confidentiality of your data. It is equally important to manage and monitor your system after installation to ensure that your data is protected from unauthorized access and misuse.

The Secure installation and configuration chapter provides secure installation and configuration guidelines, and the Security features chapter describes the security features provided in the Empirica Signal software to help you manage and monitor your system.

General security principles

  • Require strong, complex application and database passwords.

    Create a password policy to establish password requirements. For example, require a minimum password length and at least one of each of the following types of characters:

    • Alphabetic

    • Non-alphabetic

    • Numeric

    • Uppercase character

    • Lowercase character

  • Keep passwords secure.

    When you create user accounts in the Empirica Signal application, send users their user names and initial passwords in separate email messages. Instruct your users not to share or write down passwords, or to store passwords in files on their computers. Additionally, require users to change their passwords upon first use.

  • Keep software up to date.

    Keep all software versions current by installing the latest patches for all components, including all critical security updates.

  • Implement the principle of least privilege.

    In implementing the principle of least privilege, you grant users the fewest number of permissions needed to perform their jobs. You should also review user permissions regularly to determine their relevance to users' current job responsibilities.

  • Monitor system activity.

    Review user audit records regularly to determine the user activities that constitute normal use and the activities that might indicate unauthorized use or misuse.

  • Promote policy awareness.

    Ensure that your employees are aware of Acceptable Use policies, best practices, and standard operating procedures that are relevant to the Empirica Signal application.