Sensitive Data Discovery
Sensitive Data Discovery helps organizations systematically find, understand, and classify sensitive information across Oracle database environments. It provides the visibility needed to reduce data exposure, apply consistent security controls, and support compliance with privacy and security requirements.
What it does
Sensitive Data Discovery jobs target databases to identify data elements that may be sensitive, such as personal, financial, authentication, or other regulated data, and classifies the results in a structured way so that the data can be governed appropriately. This helps teams uncover both expected and previously unknown sensitive data locations as schemas and applications change over time.
Key capabilities
-
Discovery jobs: Run once after the target registration to locate potentially sensitive columns, tables, and objects. Jobs should be scheduled and monitored to maintain continuous awareness as database content evolves.
-
Identification and classification: Detect sensitive data using Oracle-defined and user-defined sensitive types and categories (for example, identifiers and contact details), then organize findings for review and governance.
-
Fleet-wide visibility: Review discovery outcomes across targets, including summary metrics and target-level details, to understand where sensitive data resides and prioritize remediation or policy enforcement.
Prerequisites for Discovering Sensitive Data
Before sensitive types and categories can be created, an administrator must enable the required permissions (and gather statistics) on the target database. After the target is registered, Oracle DBSecCentral runs a Sensitive Data Discovery job using these permissions. To run Discovery job again and keep results current, an auditor or super auditor must schedule additional discovery jobs.
-
An
administratormust enable user privileges for and run statistics gathering on the target Oracle Database. See Preparing Targets for Data Discovery or Global Sets in the Oracle DBSecCentral Administrator's Guide for more information. -
After target registration, Oracle DBSecCentral runs Sensitive Data Discovery. For subsequent scans, schedule discovery jobs. SeeRetrieving Sensitive Data for Oracle Database Targets for more information.
-
You must be an
auditororsuper auditorto use Sensitive Data Discovery.
Data Discovery Summary
Discovery Summary provides a consolidated view of all sensitive data discovery jobs that have been executed in Oracle DBSecCentral. It offers both high-level statistics and detailed target-level insights, empowering users to monitor sensitive data exposure and discovery progress across connected environments. You can also schedule discovery jobs for one or more targets from the Summary page.
Data discovery summary: A summary panel presenting quick metrics on discovery job outcomes:
-
Targets scanned for sensitive data
-
Targets not scanned for sensitive data
-
Sensitive types discovered
-
Sensitive objects discovered
-
Sensitive values discovered
Top Targets, Categories, and Types (by sensitive values): Visualization panels identifying areas of highest sensitivity by value count. Each chart is interactive and users can select on a specific value or data point to open a more detailed discovery summary or related report for that target, category, or type:
-
Top targets (by sensitive values): Databases or environments with the largest volumes of sensitive data.
-
Top sensitive categories (by sensitive values): Leading types of sensitive data found.
-
Top sensitive types (by sensitive values): Specific sensitive types with the highest number of discovered values.
Fleetwide sensitive data discovery details
A detailed table showing per-target discovery outcomes:
-
Target: The database or environment under review.
-
Discovered sensitive types: Number of distinct sensitive types found in each target.
-
Sensitive values: Number of sensitive values found in each target.
-
Last discovered: Timestamp of the most recent discovery scan for that target.
-
Next scheduled discovery: Timestamp when the next discovery job is planned.
-
Repeats every: Frequency at which discovery jobs are automatically repeated.
Data Discovery Configuration
Discovery Configuration enables auditors to manage sensitive type groups and user-defined sensitive types for sensitive data discovery within Oracle DBSecCentral. This configuration helps in identifying and classifying sensitive information stored across various database targets.
There are two key sections within the Discovery Configuration page: Sensitive type groups and User-defined sensitive types.
Sensitive type groups
This section displays a list of sensitive type groups used in sensitive data discovery.
-
Oracle-defined groups: Predefined by Oracle, these groups help quickly assign comprehensive or specialized sensitive type sets to your targets. There are four Oracle-defined groups:
-
Financial and identification info group: Oracle defined group containing all sensitive types pertaining to financial and identification information.
-
Health and identification info group: Oracle defined group containing all sensitive types pertaining to health and identification information.
-
Oracle comprehensive group: Oracle defined group containing all predefined sensitive types.
-
Oracle essential group: Oracle defined group containing 21 most prevalent sensitive types across multiple categories.
-
-
User-defined groups: Custom groups that can be defined and managed as needed.
Within this section, there are four table columns:
-
Sensitive type groups: The group name.
-
Type: Indicates if the group is Oracle-defined or user-defined.
-
Assigned targets: Databases or targets currently assigned to this group.
-
Description: Brief details of what the group includes.
Actions
-
Create sensitive type group: Define a new custom group of sensitive data types.
-
Enter a Sensitive type group name.
-
(Optional) Enter a description.
-
Under Available sensitive types, select sensitive type(s) you want to add.
-
Select Add.
-
The added types will populate under the Selected sensitive types section. If you wish to remove any of them, select sensitive type(s) and then select Remove.
-
Once the Selected sensitive types list is finished, select Save.
-
-
Delete: Remove selected groups.
-
Select one or more sensitive type groups you want to delete. Note: You can only delete user-defined groups, not Oracle-defined.
-
Confirm you want to Delete or Cancel.
-
-
Assign: Assign selected type groups to specific database targets.
-
Select a sensitive type group you want to assign.
-
Select Assign.
-
Select target(s) from the displayed list.
-
Select Assign to just assign the sensitive type group to target(s) or select Assign & discover to also discover.
-
User-defined sensitive types
This section enables searching, viewing, deleting, or managing custom sensitive data types created by users.
Actions
-
Create sensitive type: Add a new sensitive data type.
-
Select Create sensitive type.
-
Enter the Name of the sensitive type.
-
(Optional) Enter the Description.
-
Select a Category. To create a sensitive category, select the + button.
-
Enter a sensitive category name.
-
(Optional) Enter a sensitive category description.
-
Select Save.
-
-
(Optional) Enter a Column name pattern.
-
Select Test to validate and test pattern.
-
Enter Sample data.
-
Select Test.
Note: Select Copy from examples to copy a name pattern.
-
-
(Optional) Enter a Comment pattern.
-
Select Test to validate and test pattern.
-
Enter Sample data.
-
Select Test.
Note: Select Copy from examples to copy a comment pattern.
-
-
(Optional) Enter a Data pattern.
-
Select Test to validate and test pattern.
-
Enter Sample data.
-
Select Test.
Note: Select Copy from examples to copy a data pattern.
-
-
Select Save.
-
-
Delete: Remove selected user-defined sensitive types.
-
Select one or more sensitive type groups you want to delete.
-
Select Delete.
Note: Categories related to the selected sensitive types will also be deleted, if they do not have any other associated sensitive types.
-
Confirm you want to Delete or Cancel.
-