About Global Sets

Global Sets enable you to create reusable collections of commonly used values. You can create the following types of Global Sets:

For any supported target database:

For Oracle Database targets:

For IP addresses, OS users, client programs, and database users, you can manually add values or import them into a Global Set.

For Oracle Database targets, Global Sets can also be populated using the results of the User Assessment and Sensitive Data Discovery jobs. User Assessment identifies privileged users and database roles, while Sensitive Data Discovery identifies sensitive schemas and sensitive objects. Run these jobs manually or schedule them to keep the Global Sets up to date. After the jobs complete, you can add the discovered items to the corresponding Global Sets.

Global Sets can be reused across Audit, Database Vault (DV), Database Firewall (DBFW), SQL Firewall (SQLFW), and Alert policies, as well as in reports. Using Global Sets helps maintain consistent configurations and simplifies policy management across multiple target databases.

Related Topics

Prerequisites for Creating Global Privileged User and Sensitive Object Sets

Before global privileged user, database roles, sensitive schema, and sensitive object sets can be created, an administrator must enable the permissions on the Oracle Database to run the discovery and user assessment jobs and the jobs must be initiated and scheduled.

Creating a Global Set

You can use Global sets in Audit policies, DV policies, SQL Firewall policies, and Alert policies, in addition to the Database Firewall policies. You can create IP Address, OS User, Client Program, and Database User sets using any type of target database.

To add elements to a global set:

  1. Select Discovery & Classify.

  2. Within the left navigation menu, select Global Sets.

  3. Expand one of the sections and select Add.

  4. Enter a Name for the global set.

  5. Optionally, enter a Description for the global set.

  6. For IP Address, OS User, Client Program, Database User, Database Role, and Sensitive Schema sets you can either select From Collected Data, Enter Values, or File Import. For Privileged User or Sensitive Object sets you can only select Add.

  7. Elements can be added to global sets in one or more of the following three ways, From Collected Data, Enter Values, or File Import.

    • From Collected Data - Allows you to select specific elements from your targets.
      1. Select one or more targets in the Available column and move them to the Selected column using the arrows. You can also search for targets as well.

      2. Select if you want to view data from the last 24 hours, week, month, or a specific time period. This step is not applicable for Database Role sets and Sensitive Schema sets.

      3. Select Search.

      4. Select the element(s) you would like added to the global set.

    • Enter Values - Allows you to type multiple items at once so that the elements can be added in bulk to the global set. Elements can be entered as a comma separated list or one element per line. It is also possible to use both separation methods.

    • File Import - Allows you to upload a .txt file to add elements to a global set at once. The file can contain elements as a comma separated list or one element per line. It is also possible to use both separation methods.

    Note: If you’re importing a file, it must be encoded in the UTF-8 format.

  8. Select Save once you have added elements to the global set.

Creating Privileged User Sets

Privileged users are identified on your target Oracle Databases through User Assessment.

  1. Select Discovery & Classify.

  2. Within the left navigation menu, select Global Sets.

  3. Expand the Privileged User Set section and select Add.

  4. Enter a Name for the global set.

  5. Optionally, enter a Description for the global set.

  6. Select one or more targets in the Available column and move them to the Selected column using the arrows. You can also search for targets as well.

  7. Select all the users you would like to add to the set. Users can be searched for as well.

  8. Select Add.

  9. Select Save.

Creating Sensitive Object Global Sets

Sensitive objects are identified on your target Oracle Databases through Sensitive Data Discovery job.

  1. Select Discovery & Classify.

  2. Within the left navigation menu, select Global Sets.

  3. Expand the Sensitive Object Set section and select Add.

  4. Enter a Name for the global set.

  5. Optionally, enter a Description for the global set.

  6. Select one or more targets in the Available column and move them to the Selected column using the arrows. You can also search for targets as well.

  7. Select categories. By default some of the sensitive categories are listed in the selected column and can be removed using the filters.

    Sensitive categories and types available for selection include:

    • Identification Information: Includes sensitive types for national, personal, and public identifiers. Examples are US Social Security Number (SSN), Canadian Social Insurance Number (SIN) and other national IDs, Visa Number, and Full Name.

    • Biographic Information: Includes sensitive types for address, family data, extended PII, and restricted processing data. Examples are Full Address, Mother's Maiden Name, Date of Birth, and Religion.

    • IT Information: Includes sensitive types for user IT data and device data. Examples are User ID, password, and IP Address.

    • Financial Information: Includes sensitive types for payment card data and bank account data. Examples are Card Number, Card Security PIN, and Bank Account Number.

    • Healthcare Information: Includes sensitive types for health insurance data, healthcare provider data, and medical data. Examples include Health Insurance Number, Healthcare Provider, and Blood Type.

    • Employment Information: Includes sensitive types for employee basic data, organization data, and compensation data. Examples are Job Title, Termination Date, Income, and Stock.

    • Academic Information: Includes sensitive types for student basic data, institution data, and performance data. Examples are Financial Aid, College Name, Grade, and Disciplinary Record.

  8. Select all the users you'd like to add to the set. Users can be searched for as well.

  9. Select Add.

  10. Select Save.

Viewing Where Global Sets Are Used

Global Sets allow you to see where global sets are used. This can help identify what policies will be affected if a Global Set is modified.

  1. Log in to Oracle Database Security Central Console as an auditor.

  2. Select Global Sets

  3. Select a global set.

  4. View the Used In table to determine where the selected global set is used.

Related Topics

Modifying Global Sets

Modifying elements in a global set allows you to retain the global set while still being able to add or remove elements to or from the set. Modifying a global set makes it easier to update your Policies (Audit, Database Vault, SQL Firewall, Database Firewall, or Alert Policies) based on changes to your targets or specific needs, without having to create new sets.

Adding Elements

Elements can be added to all existing sets manually or in bulk for IP Address, OS User, Client Program, Database User sets, Database Role sets, and Sensitive schema sets.

  1. Select the Discovery & Classify tab.

  2. Within the left navigation menu, select Global Sets.

  3. Expand one of the sections and select on an existing global set.

  4. For IP Address, OS User, Client Program, Database User, Database Role, and Sensitive Schema sets you can either select Add From File, Add From Collected Data, or Add. For Privileged User or Sensitive Object sets you can only select Add.

  5. If you clicked Add, in the field that appears type the element(s) you would like to add. Elements can be entered as a comma separated list or one element per line.

  6. If you clicked Add From File or Add From Collected Data the process is the same as when creating a new global set.

    Note: If you’re importing a file, it must be encoded in the UTF-8 format.

  7. Select Save.

Deleting Elements

Elements can be removed from all existing sets manually.

  1. Select the Discovery & Classify tab.

  2. Within the left navigation menu, select Global Sets.

  3. Expand one of the sections and select on an existing global set.

  4. Select one or more elements from the list that you would like to remove from the global set. You can also search for specific elements as well.

  5. Select Delete.

  6. Select Save.

Understanding the Impact of Modifying Global Sets

When global sets are modified, policies that use the global set will need to be deployed again.

From the Global Sets page you can see which of your global sets are currently in use and where they are used. Whenever any set that is in use is modified, i.e. elements are added or removed from it, you will see a dialog box of policies that use the set.

Note: You can save the modified global set only if all the newly added elements are valid for every policy in which the global set is currently used.

These policies will automatically go into a status of Deployment Required. Multiple policies in this state can be selected and deployed from the Policy Console section. For more information see, Policy Management.

The Deployment Required status is displayed only for Database Firewall policies. For Audit, SQL Firewall, and DV policies, a banner appears on the respective policies page indicating that redeployment is needed.

For example, consider the following scenario: There is a global set called AllowedUsers that consists of UserA and UserB which is currently in use by deployed database firewall policy, Policy1. If the AllowedUsers set is modified to additionally include UserC, Policy1 will go into a Deployment Required status. Until Policy1 is deployed again the database firewall will only allow traffic from UserA and UserB. Once Policy1 is deployed again then the database firewall will allow traffic from UserA, UserB, and UserC.

Note: Policies will go into the Deployment Required status if any modification occurs to a set, even if that modification is undone. For example, if you add an element to a set, but then remove that element shortly after so that the set includes only the same elements as it did previously, any policies that use the set will still be marked with Deployment Required.

Deleting a Global Set

Global sets can be deleted if it is not in use by any of the components.

  1. Select the Discovery & Classify tab.

  2. Within the left navigation menu, select Global Sets.

  3. Expand one of the sections and select the global set that is not in use.

  4. Select Delete.