Introducing Oracle Database Security Central

Before you start using Oracle Database Security Central, you should understand how its components such as targets and policies work.

Downloading the Latest Version of This Manual

Before using Oracle Database Security Central, you should ensure that you have the latest version of the documentation.

You can download the latest version of this manual from the following website:

https://docs.oracle.com/en/database/oracle/database-security-central/sigau/index.html

You can find documentation for other Oracle products at the following website:

https://docs.oracle.com

Learning About Oracle Database Security Central

You should understand the features, components, users, and deployment of Oracle Database Security Central.

To find this information, refer to Oracle Database Security Central Concepts Guide.

The Auditor’s Role

An auditor should understand and assess the security risks across the database fleet, including configuration weaknesses, user and privilege-related risks, and sensitive-data exposure. Using Oracle Database Security Central, the auditor reviews risk findings, determines their severity and business impact, and prioritizes the issues that require attention. The auditor then works with database and security teams to plan appropriate mitigation actions, such as correcting insecure configurations, reducing unnecessary privileges, strengthening account controls, and protecting sensitive data.

As part of ongoing mitigation and Compliance360 activities, the auditor continuously monitors database activity, alerts, audit coverage, and security-policy compliance across the fleet. The auditor validates that required controls are enabled and operating effectively, investigates notable events or exceptions, and tracks remediation progress until risks are resolved. Through regular assessments and reviews, the auditor helps maintain a strong security and compliance posture across the organization’s databases.

An auditor uses the Oracle Database Security Central console to configure the following:

Auditor Roles in Oracle Database Security Central

There are three auditor roles in Oracle Database Security Central, with different access levels:

See Also:

Understanding Targets

A target is any supported database or non-database that you monitor with Oracle Database Security Central.

Targets can be monitored by the Audit Vault Agent, the Database Firewall, or the SQL Firewall.

The Oracle Database Security Central administrator creates and configures targets, providing host addresses, usernames, passwords, and other necessary information.

For a target to be monitored by Database Firewall, the administrator must configure the Database Firewall, and also configure a monitoring point for every target.

Once targets are configured, an auditor can do the following for each one:

Super auditors can create target groups for access control purposes. Super auditors grant auditors access to individual targets or to target groups.

See Also: Managing Targets

Understanding Firewall Policies

A Firewall policy monitors Oracle Database statements, objects, privileges, or fine-grained auditing.

See Also:

Understanding Audit Policies and Audit Data Collection

Learn how audit policies determine what audit data is collected.

See Also:

Understanding Database Vault Policies

Learn about how Database Vault can be used to protect your database.

See Also:

Configuring Alerts and Notifications

Oracle Database Security Central lets you define rule-based alerts on audit records and specify notification actions for those alerts.

Whenever an audit event meets the rule or condition defined in the alert definition, an alert is raised and a notification is sent as specified. You can define alerts by type of target, the number of times an event occurs, and by using available fields in audit records to define a Boolean condition that must be met. You can also configure email templates to be used for alert notifications.

You can monitor and respond to alerts from the Oracle Database Security Central console and from alert reports.

See Also: Creating Alerts

Generating Reports

As an Oracle Database Security Central auditor, you can generate various audit reports for the targets to which you have access.

You can schedule, print, and/or email the reports to others, in PDF or XLS format. Reports include information on audit data, assessments, and stored procedures. You can also generate compliance reports to meet regulations associated with credit card, financial, data protection, and health care-related data.

Oracle Database Security Central also lets you browse and customize report data interactively, and upload your own custom reports created with third party tools.

See Also:

Creating Users and Managing Access

A super auditor creates auditor accounts, and manages auditor access to targets and target groups.

See Also: Managing Access and Other Settings for information on these functions.

Logging in and Understanding the Oracle Database Security Central Console UI

After you log in to the Oracle Database Security Central console, you can work with various tabbed pages and lists of objects.

Logging in to the Oracle Database Security Central Console

To log in to the Oracle Database Security Central console, you must have a valid user name and password.

To log in to the Oracle Database Security Central console:

  1. From a browser, enter the following URL:

    https://*host*/console

    where host is the server where you installed Audit Vault Server.

    For example:

    https://192.0.2.1/console
  2. In the Login page, enter your user name and password, and then select Login.

    The Home page appears.

Understanding the Tabs in the Oracle Database Security Central Console UI

An auditor or super auditor can see the auditor’s dashboard on the home page and the functions that are available for the auditor roles.

Home page

The Home tab on the console has the following sections:

There is an option to filter the display by time period.

Other tabs

Working with Lists of Objects in the UI

Throughout the Audit Vault Server UI, you will see lists of objects such as reports, users, targets, firewall policies, and so on.

You can filter and customize any of these lists of objects in the same way as you can for Oracle Database Security Central reports. This section provides a summary of how you can filter and custom the display of lists of objects.

See Also: Filtering Data in a Report

To filter and control the display of lists of objects in the Audit Vault Server UI:

  1. Select the report, list, or column heading.

  2. You can customize the list, by selecting any of the following available options:

    • Sort Ascending

    • Sort Descending

    • Hide Column

    • Control Break