Installing Oracle Database Security Central Securely to Protect Your Data
Learn how to securely install Oracle DBSecCentral to protect your data.
Installing Oracle Database Security Central Securely
Learn to securely install Oracle Database Security Central.
Oracle Audit Vault Server installs in a secure state by default. Therefore, it is important to be careful if you change any of the default settings because your changes may compromise the security of your setup.
See Also: Oracle Database Security Central Installation Guide for details of the installation.
Protecting Your Data
Consider account naming, password use, and other guidelines to better enable Oracle DBSecCentral to protect your data.
Consider following these guidelines to protect your data:
-
Account Names and Passwords: Use secure passwords for the Oracle Database Security Central console UI, as well as for the
root,support, andsysaccounts and keep these passwords safe. -
Administrator Accounts: Do not share Oracle Database Security Central Administrator accounts.
-
Strong Password Policies: Encourage users to adopt strong passwords.
-
Installed Accounts: Oracle Database Security Central embeds operating system and database accounts. Do not add new accounts of this type. Do not unlock the existing accounts. Doing so may compromise the security of the Oracle Database Security Central system.
-
Secure Archiving: Oracle Database Security Central sends archive data over the network. Secure both the archive destination and intermediate network infrastructure.
-
Remote Access: The Settings of the services page of Oracle Database Security Central console controls access to:
-
web console
-
shell (ssh)
-
SNMP
Follow these guidelines when granting remote access:
-
Grant access only if you need it for a specific task and then revoke access when that task is completed.
-
Restrict access by IP address. Do this immediately after installing the system.
-
Grant terminal (shell) access only when doing a patch update or when requested to do so by the documentation or by Oracle support.
-