Planning Your Oracle Database Security Central System Configuration

Learn about planning your system configuration for Oracle DBSecCentral.

Guidance for Planning Your Oracle Database Security Central Configuration

Learn about the steps for planning your Oracle Database Security Central configuration.

The steps in this section summarize the planning steps with links to specific instructions in this user guide.

See Also: Oracle Database Security Central Concepts Guide for guidance on planning deployments of Oracle Audit Vault Server, Oracle Audit Vault Agent, and Oracle Database Firewall.

Step 1: Plan Your Oracle Audit Vault Server Configuration

Plan your Oracle Audit Vault Server configuration.

In this step, plan whether to configure a resilient pair of servers, whether to change the network configuration settings that were made during the installation, and how to configure optional services.

Step 2: Plan Your Oracle Database Firewall Configuration

Learn how to plan your Oracle Database Firewall configuration.

If you are using Oracle Database Firewall, then plan how many you need, which target databases they will protect, where to place them in the network, whether they will be for monitoring only or for monitoring and blocking mode, and whether to configure a resilient pair of firewalls. Also plan whether to change the Oracle Database Firewall network configuration that was specified during installation.

Following are the list of activities you would like to review:

Step 3: Plan Your Oracle Audit Vault Agent Deployments

If you’re deploying the Audit Vault Agent, determine the targets for which you want to collect audit data and identify their host computers.

You register these hosts with Oracle Database Security Central and deploy the Audit Vault Agent on each of them. Then you register each target in the Audit Vault Server.

Note: You can use agentless collection instead of the Audit Vault Agent for Oracle Database table audit trails and Microsoft SQL Server directory audit trails for .sqlaudit and .xel (Extended Events) files. The total number of audit trails configured for agentless collection must not exceed 20. See Adding Audit Trails with Agentless Collection.

See Also:

Step 4: Plan Your Audit Trail Configurations

If you’re deploying the Audit Vault Agent or using agentless collection to collect audit data, then you need to configure audit trails.

Use these guidelines to plan audit trail configurations for the targets from which you want to extract audit data. The type of audit trail that you select depends on the target type, and in the case of an Oracle Database target, the type of auditing that you’ve enabled in Oracle Database.

To plan the target audit trail configuration:

  1. Ensure that auditing is enabled on the target. For Oracle Database targets, find the type of auditing that Oracle Database uses.

    See Ensuring that Auditing is Enabled in a Target.

  2. If you’re deploying the Audit Vault Agent, ensure that it’s installed on a host computer. This is also called the agent machine.

    See Deploying the Audit Vault Agent on Host Computers.

    Note: the Audit Vault Agent for up to 20 Oracle Database table audit trails. In addition, you can also use agentless collection for Microsoft SQL Server directory audit trails for .sqlaudit and .xel (extended events). The total number of audit trails for agentless collection should not exceed 20. See Adding Audit Trails with Agentless Collection.

  3. Determine which type of audit trail to collect.

    See this audit trail summary table for the types of audit trails that you can configure for each target type and supported platform.

  4. Familiarize yourself with the procedures to register a target and configure an audit trail.

  5. If you’re collecting audit data from MySQL or IBM DB2 targets, see the additional steps in the following topics:

See Also: Requirements for Collecting Audit Data from Targets

Step 5: Plan for High Availability

Learn how to plan for high availability.

In this step, consider the high availability options that are outlined in High Availability in Oracle DBSecCentral.

Step 6: Plan User Accounts and Access Rights

Learn how to plan your user accounts and their access rights.

As a super administrator, you can create other super administrators and administrators. Super administrators can see and modify any target. Administrators have access to the targets that you enable them to access. In this step, determine how many super administrators and administrators you create accounts for, and to which targets the administrators will have access.

See Also: Managing User Accounts and Access