Separation of Duties
Oracle Database Security Central offers multiple roles as part of the separation of duties between auditors and administrators.
To provide greater security, the Oracle Database Security Central administrator and auditor roles have different user interfaces, and different user accounts. This separation of interfaces and accounts ensures that there is a separation of duties between these two roles. In addition to these Oracle Database Security Central user accounts, you can also set up user accounts on your targets as necessary to access targets for collecting audit data. This is needed by the Audit Vault Agent for connecting to the target and collecting the audit data from the audit trails. Oracle Database Security Central provides scripts to set up these user accounts on database targets, and guidance for other types of targets.
The following table shows the user accounts in Oracle Database Security Central.
Table 1 Oracle Database Security Central User Accounts
| Account | Description |
|---|---|
| Super Administrator | Super administrators configure and maintain the Oracle Database Security Central system, including Audit Vault Server settings such as network settings, high availability, data retention policies, etc. The super administrator can create other administrators or super administrators, and has access to all targets. The super administrator can also grant access to specific targets to other administrators. |
| Administrator | The administrator can perform a subset of the system configuration tasks that a super administrator can, such as registering hosts and targets, running archive jobs, etc. Administrators can also manage targets for which they have been granted access by a super administrator. An administrator cannot create another administrator. This can be performed by a super administrator only. |
| Super Auditor | The super auditor can create firewall policies, provision audit policies for Oracle Database targets, and specify settings for target such as whether to enable stored procedure auditing. Super auditors also generate reports, and create alerts and notifications. The super auditor can access all targets, create auditor or super auditor users, and grant access to specific targets to those users. |
| Auditor | Auditors can perform all the functions of super auditors, but only for the targets to which they have access. |
Additional accounts are provided for diagnostics and used under the guidance of Oracle Support.