About Global Sets
Global Sets enable you to create reusable collections of commonly used values. You can create the following types of Global Sets:
For any supported target database:
- IP addresses
- Operating system (OS) users
- Client programs
- Database users
For Oracle Database targets:
- Privileged users
- Database roles
- Sensitive schemas
- Sensitive objects
For IP addresses, OS users, client programs, and database users, you can manually add values or import them into a Global Set.
For Oracle Database targets, Global Sets can also be populated using the results of the User Assessment and Sensitive Data Discovery jobs. User Assessment identifies privileged users and database roles, while Sensitive Data Discovery identifies sensitive schemas and sensitive objects. Run these jobs manually or schedule them to keep the Global Sets up to date. After the jobs complete, you can add the discovered items to the corresponding Global Sets.
Global Sets can be reused across Audit, Database Vault (DV), Database Firewall (DBFW), SQL Firewall (SQLFW), and Alert policies, as well as in reports. Using Global Sets helps maintain consistent configurations and simplifies policy management across multiple target databases.
Related Topics
Prerequisites for Creating Global Privileged User and Sensitive Object Sets
Before global privileged user, database roles, sensitive schema, and sensitive object sets can be created, an administrator must enable the permissions on the Oracle Database to run the discovery and user assessment jobs and the jobs must be initiated and scheduled.
-
An
administratormust enable user privileges for and run statistics gathering on the target Oracle Database. See Preparing Targets for Data Discovery or Global Sets in the Oracle DBSecCentral Administrator's Guide for more information. -
The sensitive data discovery job needs to be initiated and scheduled. SeeRetrieving Sensitive Data for Oracle Database Targets for more information.
-
The user assessment job needs to be initiated and scheduled. SeeRetrieving User Assessment Data for Oracle Database Targets for more information.
-
You must be an
auditororsuper auditorto use Global Sets.
Creating a Global Set
You can use Global sets in Audit policies, DV policies, SQL Firewall policies, and Alert policies, in addition to the Database Firewall policies. You can create IP Address, OS User, Client Program, and Database User sets using any type of target database.
To add elements to a global set:
-
Select Discovery & Classify.
-
Within the left navigation menu, select Global Sets.
-
Expand one of the sections and select Add.
-
Enter a Name for the global set.
-
Optionally, enter a Description for the global set.
-
For IP Address, OS User, Client Program, Database User, Database Role, and Sensitive Schema sets you can either select From Collected Data, Enter Values, or File Import. For Privileged User or Sensitive Object sets you can only select Add.
-
Elements can be added to global sets in one or more of the following three ways, From Collected Data, Enter Values, or File Import.
- From Collected Data - Allows you to select specific elements from your targets.
-
Select one or more targets in the Available column and move them to the Selected column using the arrows. You can also search for targets as well.
-
Select if you want to view data from the last 24 hours, week, month, or a specific time period. This step is not applicable for Database Role sets and Sensitive Schema sets.
-
Select Search.
-
Select the element(s) you would like added to the global set.
-
-
Enter Values - Allows you to type multiple items at once so that the elements can be added in bulk to the global set. Elements can be entered as a comma separated list or one element per line. It is also possible to use both separation methods.
- File Import - Allows you to upload a .txt file to add elements to a global set at once. The file can contain elements as a comma separated list or one element per line. It is also possible to use both separation methods.
Note: If you’re importing a file, it must be encoded in the UTF-8 format.
- From Collected Data - Allows you to select specific elements from your targets.
-
Select Save once you have added elements to the global set.
Creating Privileged User Sets
Privileged users are identified on your target Oracle Databases through User Assessment.
-
Select Discovery & Classify.
-
Within the left navigation menu, select Global Sets.
-
Expand the Privileged User Set section and select Add.
-
Enter a Name for the global set.
-
Optionally, enter a Description for the global set.
-
Select one or more targets in the Available column and move them to the Selected column using the arrows. You can also search for targets as well.
-
Select all the users you would like to add to the set. Users can be searched for as well.
-
Select Add.
-
Select Save.
Creating Sensitive Object Global Sets
Sensitive objects are identified on your target Oracle Databases through Sensitive Data Discovery job.
-
Select Discovery & Classify.
-
Within the left navigation menu, select Global Sets.
-
Expand the Sensitive Object Set section and select Add.
-
Enter a Name for the global set.
-
Optionally, enter a Description for the global set.
-
Select one or more targets in the Available column and move them to the Selected column using the arrows. You can also search for targets as well.
-
Select categories. By default some of the sensitive categories are listed in the selected column and can be removed using the filters.
Sensitive categories and types available for selection include:
-
Identification Information: Includes sensitive types for national, personal, and public identifiers. Examples are US Social Security Number (SSN), Canadian Social Insurance Number (SIN) and other national IDs, Visa Number, and Full Name.
-
Biographic Information: Includes sensitive types for address, family data, extended PII, and restricted processing data. Examples are Full Address, Mother's Maiden Name, Date of Birth, and Religion.
-
IT Information: Includes sensitive types for user IT data and device data. Examples are User ID, password, and IP Address.
-
Financial Information: Includes sensitive types for payment card data and bank account data. Examples are Card Number, Card Security PIN, and Bank Account Number.
-
Healthcare Information: Includes sensitive types for health insurance data, healthcare provider data, and medical data. Examples include Health Insurance Number, Healthcare Provider, and Blood Type.
-
Employment Information: Includes sensitive types for employee basic data, organization data, and compensation data. Examples are Job Title, Termination Date, Income, and Stock.
-
Academic Information: Includes sensitive types for student basic data, institution data, and performance data. Examples are Financial Aid, College Name, Grade, and Disciplinary Record.
-
-
Select all the users you'd like to add to the set. Users can be searched for as well.
-
Select Add.
-
Select Save.
Viewing Where Global Sets Are Used
Global Sets allow you to see where global sets are used. This can help identify what policies will be affected if a Global Set is modified.
-
Log in to Oracle Database Security Central Console as an
auditor. -
Select Global Sets
-
Select a global set.
-
View the Used In table to determine where the selected global set is used.
Related Topics
Modifying Global Sets
Modifying elements in a global set allows you to retain the global set while still being able to add or remove elements to or from the set. Modifying a global set makes it easier to update your Policies (Audit, Database Vault, SQL Firewall, Database Firewall, or Alert Policies) based on changes to your targets or specific needs, without having to create new sets.
Adding Elements
Elements can be added to all existing sets manually or in bulk for IP Address, OS User, Client Program, Database User sets, Database Role sets, and Sensitive schema sets.
-
Select the Discovery & Classify tab.
-
Within the left navigation menu, select Global Sets.
-
Expand one of the sections and select on an existing global set.
-
For IP Address, OS User, Client Program, Database User, Database Role, and Sensitive Schema sets you can either select Add From File, Add From Collected Data, or Add. For Privileged User or Sensitive Object sets you can only select Add.
-
If you clicked Add, in the field that appears type the element(s) you would like to add. Elements can be entered as a comma separated list or one element per line.
-
If you clicked Add From File or Add From Collected Data the process is the same as when creating a new global set.
Note: If you’re importing a file, it must be encoded in the UTF-8 format.
-
Select Save.
Deleting Elements
Elements can be removed from all existing sets manually.
-
Select the Discovery & Classify tab.
-
Within the left navigation menu, select Global Sets.
-
Expand one of the sections and select on an existing global set.
-
Select one or more elements from the list that you would like to remove from the global set. You can also search for specific elements as well.
-
Select Delete.
-
Select Save.
Understanding the Impact of Modifying Global Sets
When global sets are modified, policies that use the global set will need to be deployed again.
From the Global Sets page you can see which of your global sets are currently in use and where they are used. Whenever any set that is in use is modified, i.e. elements are added or removed from it, you will see a dialog box of policies that use the set.
Note: You can save the modified global set only if all the newly added elements are valid for every policy in which the global set is currently used.
These policies will automatically go into a status of Deployment Required. Multiple policies in this state can be selected and deployed from the Policy Console section. For more information see, Policy Management.
The Deployment Required status is displayed only for Database Firewall policies. For Audit, SQL Firewall, and DV policies, a banner appears on the respective policies page indicating that redeployment is needed.
For example, consider the following scenario: There is a global set called AllowedUsers that consists of UserA and UserB which is currently in use by deployed database firewall policy, Policy1. If the AllowedUsers set is modified to additionally include UserC, Policy1 will go into a Deployment Required status. Until Policy1 is deployed again the database firewall will only allow traffic from UserA and UserB. Once Policy1 is deployed again then the database firewall will allow traffic from UserA, UserB, and UserC.
Note: Policies will go into the Deployment Required status if any modification occurs to a set, even if that modification is undone. For example, if you add an element to a set, but then remove that element shortly after so that the set includes only the same elements as it did previously, any policies that use the set will still be marked with Deployment Required.
Deleting a Global Set
Global sets can be deleted if it is not in use by any of the components.
-
Select the Discovery & Classify tab.
-
Within the left navigation menu, select Global Sets.
-
Expand one of the sections and select the global set that is not in use.
-
Select Delete.