Sensitive Data Discovery

Sensitive Data Discovery helps organizations systematically find, understand, and classify sensitive information across Oracle database environments. It provides the visibility needed to reduce data exposure, apply consistent security controls, and support compliance with privacy and security requirements.

What it does

Sensitive Data Discovery jobs target databases to identify data elements that may be sensitive, such as personal, financial, authentication, or other regulated data, and classifies the results in a structured way so that the data can be governed appropriately. This helps teams uncover both expected and previously unknown sensitive data locations as schemas and applications change over time.

Key capabilities

Prerequisites for Discovering Sensitive Data

Before sensitive types and categories can be created, an administrator must enable the required permissions (and gather statistics) on the target database. After the target is registered, Oracle DBSecCentral runs a Sensitive Data Discovery job using these permissions. To run Discovery job again and keep results current, an auditor or super auditor must schedule additional discovery jobs.

Data Discovery Summary

Discovery Summary provides a consolidated view of all sensitive data discovery jobs that have been executed in Oracle DBSecCentral. It offers both high-level statistics and detailed target-level insights, empowering users to monitor sensitive data exposure and discovery progress across connected environments. You can also schedule discovery jobs for one or more targets from the Summary page.

Data discovery summary: A summary panel presenting quick metrics on discovery job outcomes:

Top Targets, Categories, and Types (by sensitive values): Visualization panels identifying areas of highest sensitivity by value count. Each chart is interactive and users can select on a specific value or data point to open a more detailed discovery summary or related report for that target, category, or type:

Fleetwide sensitive data discovery details

A detailed table showing per-target discovery outcomes:

Data Discovery Configuration

Discovery Configuration enables auditors to manage sensitive type groups and user-defined sensitive types for sensitive data discovery within Oracle DBSecCentral. This configuration helps in identifying and classifying sensitive information stored across various database targets.

There are two key sections within the Discovery Configuration page: Sensitive type groups and User-defined sensitive types.

Sensitive type groups

This section displays a list of sensitive type groups used in sensitive data discovery.

Within this section, there are four table columns:

Actions

User-defined sensitive types

This section enables searching, viewing, deleting, or managing custom sensitive data types created by users.

Actions