Manage Security Policies

After you create a security policy, there are a number of actions that can be taken to manage it.

Edit the Configuration of a Custom Security Policy

Edit if the activity of the Data Safe user is excluded or included in unified audit policies.

  1. Under Data Safe - Database Security, select Security policies.
  2. Select a custom security policy from the Custom security policies tab.
  3. Under Actions, select Edit config.
  4. Set the unified audit policy configurations as desired.

    Note:

    Excluding the Oracle Data Safe user for audit policies will fail for the following instances:
    • RDBMS mandatory auditing
    • Compliance policies, such as STIG and CIS
    • Any custom audit policies that are provisioned exclusively on the Oracle Data Safe user
    • Any audit policies that audit a role that is already assigned to the Oracle Data Safe user
    • Audit records generated by a traditional audit trail
  5. Select Save.

Add Unified Audit Policies to Custom Security Policies

Add unified audit policies to security policies to collect audit data on target databases.

  1. Under Data Safe - Database Security, select Security policies.
  2. Select the Custom security policies tab.
  3. Select the security policy you want to add unified audit policies to.
  4. Select the Unified audit policies tab.
  5. Select Add unified audit policy.
  6. Enter the audit policy name, description, and select the compartment the unified audit policy will be stored in.
  7. Select a unified audit policy definition.
  8. Configure the audit conditions for All users, Only a specific set of users and/or roles, or All users except a specific set of users.
  9. If applicable based on the previous step, select the users/roles to be included or excluded and the conditions for their auditing.

    Tip:

    Ensure that any attribute sets are populated in order for the audit policy to work as expected.

    You may select multiple users or roles at once. However, they must come from the same database to be selected at the same time. You may also add additional users or roles by selecting from the lists and selecting Add for each entry. You must select the type, target database (if applicable), and operation status for each.

    When adding users, you use the target database drop-down to filter the list of available users. However, any selected user names are independent of the database. For example, if user JOE appears in database1 and database2, assuming the policy is deployed to both these databases, JOE's activity will be audited in both databases regardless of which database was selected when adding JOE to the list of users to include.

    Note:

    Only one attribute set may be used in a unified audit policy and attributes sets can only be used to define included users/roles.
  10. If applicable, determine when to audit based on operation success or failure.
  11. Select Add.
  12. Deploy Security Policies

Enable or Disable Unified Audit Policies in a Custom Security Policy

Individual audit policies can be enabled or disabled once they are added to a security policy.

  1. Under Data Safe - Database Security, select Security policies.
  2. Select a custom security policy in the Custom security policies tab.
  3. Select the Unified audit policies tab.
  4. Select a unified audit policy.
  5. Select Enable policy or Disable policy.

View Unified Audit Policies on a Target Database

See what unified audit policies are deployed on a target database and the source of those policies.

  1. Under Data Safe - Database Security, select Security policies.
  2. Under Security Policies, select Unified audit policies.
  3. Select the Target summary tab.
  4. In the Actions column (...) for the row of the target database you want to view audit policies for, select View policies.

    For each applied unified audit policy, you will see the name, the audit conditions, and the security policy that the unified audit policy is a part of. If the security policy column is -, this means that the unified audit policy is applied directly on the target database, i.e., the audit policy can't be managed within Oracle Data Safe.

Update Users and Roles for Audit Policies

Change what users a policy is enabled for and operations are audited.

  1. Under Data Safe - Database Security, select Security policies.
  2. Under Security policies, select Unified audit policies
  3. Select a unified audit policy from the list.
  4. Select the Audit conditions tab.
  5. Select Edit conditions.
  6. Configure the audit conditions for All users, Only a specific set of users and/or roles, or All users except a specific set of users.
  7. If applicable based on the previous step, select the users/roles to be included or excluded and the conditions for their auditing.

    Tip:

    Ensure that any attribute sets are populated in order for the audit policy to work as expected.

    You may select multiple users or roles at once. However, they must come from the same database to be selected at the same time. You may also add additional users or roles by selecting from the lists and selecting Add for each entry. You must select the type, target database (if applicable), and operation status for each.

    When adding users you use the target database drop-down to filter the list of available users. However any selected user names are independent of the database. For example, if user JOE appears in database1 and database2, assuming the policy is deployed to both these databases, JOE's activity will be audited in both databases regardless of which database was selected when adding JOE to the list of users to include.

    Note:

    Only one attribute set may be used in a unified audit policy and attributes sets can only be used to define included users/roles.
  8. If applicable, determine when to audit based on operation success or failure.
  9. Select Save.

Import Audit Policies Into a Security Policy

You can import existing audit policies on a target database to a security policy which can then be deployed to several target databases.

  1. Under Data Safe - Database Security, select Security policies.
  2. Under Security Policies, select Unified audit policies.
  3. Select the Target Summary tab.
  4. In the Actions column (...) for the row of the target database you want to import audit policies from, select View policies.
  5. Select the unified audit policy(ies) that you want to import into a security policy.
  6. Select Import audit policies into Data Safe.
  7. Select which existing security policy you want to add the audit policy(ies) to or create a new security policy for the selected audit policy(ies).
  8. Select Import.

    Do not navigate out of import panel until the security policy status changes to Active.

The security policy can then be deployed to any number of target databases and will retain the same audit policy configuration.

Related Topics

View Security Policy Deployments

See what targets and target groups a security policy is deployed on.

To view which security policies are deployed on a particular target:

  1. Under Data Safe - Database Security, select Security policies.
  2. Under Security Policies, select Security Policy Deployments.
  3. Select the Target summary tab or the Target group summary tab.

    You will see an entry for each security policy that is deployed on a target.

  4. Select a target database (group) name to view the deployment for the specific security policy.

To view which targets a security policy is deployed on:

  1. Under Data Safe - Database Security, select Security policies.
  2. Select any policy on the Oracle predefined security policies tab or in the Custom security policies tab.
  3. View the list of target database groups or target databases that this policy is deployed on in the Target group summary and Target summary tabs.

View Details of Failed Security Policy Deployments

Viewing the deployment details of failed security policy deployments can help resolve deployment conflicts.

  1. Under Data Safe - Database Security, select Security policies.
  2. Under Security Policies, select Security Policy Deployments.
  3. Select the target name in the Needs Attention state in the Target summary tab or target group in the Target group summary tab.

    Ensure that you select the target from the row of the security policy that is not deployed properly.

  4. Use the Security policy deployment issues tab and specifically the Deployment details column to resolve the deployment issue.
  5. Select Refresh to refresh the deployment once you've resolved the issue.

Redeploy a Security Policy

After changes to the security policy, such as the configuration changes or modifying unified audit policies, security policies need to be redeployed for these changes to take effect on targets.

  1. Under Data Safe - Database Security, select Security policies.
  2. Under Security Policies, select Security Policy Deployments.
  3. In the Target group summary or Target summary tabs, select a target database group or target database that is in the Pending Deployment state.
  4. View the security policy deployment and select the associated security policy.
  5. In the security policy, select Deploy.

    This will redeploy all security policies that were already deployed to the selected target database group or target database.

Undeploy a Security Policy

  1. Under Data Safe - Database Security, select Security policies.
  2. Under Security Policies, select Security Policy Deployments.
  3. In the Target group summary or Target summary tabs, select a target database group or target database of the security policy you want to undeploy
  4. Confirm you have selected the deployment of the correct security policy and target database group or target database by viewing the Details tab.
  5. Under Actions, select Delete.
  6. Select Delete.

    This will undeploy the associated security policy on the selected target database group or target database. The security policy will see be available, this action only removes the deployment on the selected target database group or target database.