Introducing Oracle Database Security Central
Before you start using Oracle Database Security Central, you should understand how its components such as targets and policies work.
Downloading the Latest Version of This Manual
Before using Oracle Database Security Central, you should ensure that you have the latest version of the documentation.
You can download the latest version of this manual from the following website:
https://docs.oracle.com/en/database/oracle/database-security-central/sigau/index.html
You can find documentation for other Oracle products at the following website:
Learning About Oracle Database Security Central
You should understand the features, components, users, and deployment of Oracle Database Security Central.
To find this information, refer to Oracle Database Security Central Concepts Guide.
The Auditor’s Role
An auditor should understand and assess the security risks across the database fleet, including configuration weaknesses, user and privilege-related risks, and sensitive-data exposure. Using Oracle Database Security Central, the auditor reviews risk findings, determines their severity and business impact, and prioritizes the issues that require attention. The auditor then works with database and security teams to plan appropriate mitigation actions, such as correcting insecure configurations, reducing unnecessary privileges, strengthening account controls, and protecting sensitive data.
As part of ongoing mitigation and Compliance360 activities, the auditor continuously monitors database activity, alerts, audit coverage, and security-policy compliance across the fleet. The auditor validates that required controls are enabled and operating effectively, investigates notable events or exceptions, and tracks remediation progress until risks are resolved. Through regular assessments and reviews, the auditor helps maintain a strong security and compliance posture across the organization’s databases.
An auditor uses the Oracle Database Security Central console to configure the following:
-
Targets - As an auditor, you can specify audit and/or firewall policies for the target you are monitoring.
Note: For each target you are monitoring, the Oracle Database Security Central administrator must configure a target in the Audit Vault Server.
-
Unified Policy Management - For any supported database, you can use Oracle Audit Vault and Database Firewall to design Audit, Database Vault, Database Firewall, and SQL Firewall policies based on your requirements.
-
Audit Policies - For Oracle databases, you can use Oracle Database Security Central to design audit policies and provision them to the database.
-
Alerts - You can create simple or complex alerts based on conditions you specify for the targets you are monitoring. You can also specify alert notifications using email templates.
-
Audit Trails - For any target type, you can monitor the status of audit trails and see audit reports.
-
Reports - You can schedule and generate a number of audit and firewall reports in Oracle Database Security Central, create report notifications, as well as add your own customized reports.
Auditor Roles in Oracle Database Security Central
There are three auditor roles in Oracle Database Security Central, with different access levels:
-
Super Auditor - This role has access to all targets and can grant access to specific targets and groups to an auditor. A super auditor can also assign the super auditor role to others.
-
Auditor- This role can only see data for targets to which they have been granted access by a super auditor.
-
Readonly Auditor - This role has read only access to targets, audit trails, Database Firewall monitoring points, dashboard, reports, charts, access rights data, and can add filters.
See Also:
Understanding Targets
A target is any supported database or non-database that you monitor with Oracle Database Security Central.
Targets can be monitored by the Audit Vault Agent, the Database Firewall, or the SQL Firewall.
The Oracle Database Security Central administrator creates and configures targets, providing host addresses, usernames, passwords, and other necessary information.
For a target to be monitored by Database Firewall, the administrator must configure the Database Firewall, and also configure a monitoring point for every target.
Once targets are configured, an auditor can do the following for each one:
-
Analyze and investigate the risks, and plan for mitigation as per organization policies.
-
Enable stored procedure auditing (SPA)
-
If the target is a database by a Database Firewall:
-
Design and apply a firewall policy
-
View the status of configured monitoring points
-
-
If the target is an Oracle database:
-
Define and provision the Audit policies, Database Vault, or SQL Firewall policies based on your requirements.
-
Retrieve security assessment, user assessment, and discover sensitive objects for the target.
-
-
Generate a variety of reports
-
Monitor audit trail status
Super auditors can create target groups for access control purposes. Super auditors grant auditors access to individual targets or to target groups.
See Also: Managing Targets
Understanding Firewall Policies
A Firewall policy monitors Oracle Database statements, objects, privileges, or fine-grained auditing.
See Also:
-
Chapter 4 of Oracle Database Security Central Concepts Guide for detailed information.
Understanding Audit Policies and Audit Data Collection
Learn how audit policies determine what audit data is collected.
See Also:
-
Unified Policy Management chapter of the Oracle Database Security Central Concepts Guide.
Understanding Database Vault Policies
Learn about how Database Vault can be used to protect your database.
See Also:
-
Unified Policy Management chapter of the Oracle Database Security Central Concepts Guide.
Configuring Alerts and Notifications
Oracle Database Security Central lets you define rule-based alerts on audit records and specify notification actions for those alerts.
Whenever an audit event meets the rule or condition defined in the alert definition, an alert is raised and a notification is sent as specified. You can define alerts by type of target, the number of times an event occurs, and by using available fields in audit records to define a Boolean condition that must be met. You can also configure email templates to be used for alert notifications.
You can monitor and respond to alerts from the Oracle Database Security Central console and from alert reports.
See Also: Creating Alerts
Generating Reports
As an Oracle Database Security Central auditor, you can generate various audit reports for the targets to which you have access.
You can schedule, print, and/or email the reports to others, in PDF or XLS format. Reports include information on audit data, assessments, and stored procedures. You can also generate compliance reports to meet regulations associated with credit card, financial, data protection, and health care-related data.
Oracle Database Security Central also lets you browse and customize report data interactively, and upload your own custom reports created with third party tools.
See Also:
Creating Users and Managing Access
A super auditor creates auditor accounts, and manages auditor access to targets and target groups.
See Also: Managing Access and Other Settings for information on these functions.
Logging in and Understanding the Oracle Database Security Central Console UI
After you log in to the Oracle Database Security Central console, you can work with various tabbed pages and lists of objects.
Logging in to the Oracle Database Security Central Console
To log in to the Oracle Database Security Central console, you must have a valid user name and password.
To log in to the Oracle Database Security Central console:
-
From a browser, enter the following URL:
https://*host*/consolewhere host is the server where you installed Audit Vault Server.
For example:
https://192.0.2.1/console -
In the Login page, enter your user name and password, and then select Login.
The Home page appears.
Understanding the Tabs in the Oracle Database Security Central Console UI
An auditor or super auditor can see the auditor’s dashboard on the home page and the functions that are available for the auditor roles.
Home page
The Home tab on the console has the following sections:
-
Database fleet activity monitoring agents
-
Oracle Database fleet security posture
-
Key risks to review
-
Database configuration
-
Users
-
Sensitive data
-
There is an option to filter the display by time period.
Other tabs
-
Targets - Manage schedules for assessment and sensitive data discovery, setup target groups and view audit trails and monitoring points configured for a target.
-
Discover & Classify - Discover and identify sensitive data, and create reusable sets, such as IP addresses, OS users, database users, and roles, for use across Security Central features.
-
Policies - Manage Audit, Database Vault, Firewall (Oracle SQL Firewall and Database Firewall), and Alert policies.
-
Alerts - Manage alerts.
-
Reports - Generate default reports, schedule reports, customize reports online, and upload your custom reports.
-
Settings - Change your password, create and manage email distribution lists, configure email notification templates for alerts and reports, view audit trail and monitoring point status, manage user accounts and access, and view job status.
Working with Lists of Objects in the UI
Throughout the Audit Vault Server UI, you will see lists of objects such as reports, users, targets, firewall policies, and so on.
You can filter and customize any of these lists of objects in the same way as you can for Oracle Database Security Central reports. This section provides a summary of how you can filter and custom the display of lists of objects.
See Also: Filtering Data in a Report
To filter and control the display of lists of objects in the Audit Vault Server UI:
-
Select the report, list, or column heading.
-
You can customize the list, by selecting any of the following available options:
-
Sort Ascending
-
Sort Descending
-
Hide Column
-
Control Break
-