Platform Security, Operations, and Integration
Oracle Database Security Central is designed to operate within enterprise environments that require strong security controls, seamless integration with existing systems, and efficient operational management.
Securing the Platform Itself
The platform holds some of the most sensitive security data an organization possesses, so the platform itself is hardened. The runs a hardened Oracle Linux operating system. Collected data is encrypted using Transparent Data Encryption, network traffic is encrypted in transit, and Oracle Database Vault restricts access to the repository. Separation of duties between administrator and auditor roles ensures that those who manage the platform are not the same people who review the evidence it collects.
Enterprise Integration
Oracle Database Security Central is designed to integrate into existing enterprise security and operations ecosystems. It supports integration with Security Information and Event Management platforms and with third-party business intelligence and reporting tools through the documented schema. It supports enterprise identity providers for single sign-on and multifactor authentication. Operational automation is supported through the Audit Vault Command Line Interface.
Support Policy for Additional or Third-Party Software
To preserve the integrity, stability, and supportability of the platform, third-party software should not be installed directly on the appliance. Platform upgrades update the embedded operating system, so externally added libraries or software may be affected or removed. Where third-party modifications appear to contribute to an issue, Oracle may ask that the issue be reproduced on a clean Oracle Database Security Central deployment before providing assistance.