Index

A  B  C  D  E  F  G  H  I  L  M  N  O  P  R  S  T  U  V  W  

A

  • access control
    • discretionary 3.5.4
    • understanding 3
  • access mediation
  • ADD_GROUPS procedure
  • ALL_CONTROL option 8.1.3, 8.1.4, 8.1.8
  • ALL_SA_AUDIT_OPTIONS view F.1.2.1
  • ALL_SA_COMPARTMENTS view F.1.2.2, F.1.2.17
  • ALL_SA_DATA_LABELS view F.1.2.3, F.1.2.18
  • ALL_SA_GROUPS view F.1.2.4, F.1.2.19
  • ALL_SA_LABELS view F.1.2.5
  • ALL_SA_LEVELS view F.1.2.6
  • ALL_SA_POLICIES view F.1.2.7
  • ALL_SA_PROG_PRIVS view F.1.2.8
  • ALL_SA_SCHEMA_POLICIES view F.1.2.9
  • ALL_SA_TABLE_POLICIES view F.1.2.10
  • ALL_SA_USER_LABELS view F.1.2.12
  • ALL_SA_USER_LEVELS view F.1.2.13
  • ALL_SA_USER_PRIVS view F.1.2.14
  • ALL_SA_USERS view F.1.2.11
  • ALTER_GROUP_PARENT
  • ALTER_GROUPS procedure
  • ALTER_POLICY procedure
  • ANALYZE command 12.4.1
  • APPLY_SCHEMA_POLICY procedure
  • APPLY_TABLE_POLICY procedure
  • architecture, Oracle Label Security 1.6
  • AS SYSDBA clause 12.5.3
  • AUDIT_LABEL_ENABLED function E.1.4
  • AUDIT_TRAIL parameter 10.2
  • auditing
    • audit trails 10.1, 10.2, E.1.5
    • creating audit view E.1.5
    • disabling E.1.8
    • dropping audit view E.1.6
    • enabling
      • SA_AUDIT_ADMIN.AUDIT procedure E.1.2
    • finding audit options F.1.2.1
    • finding if labels are recorded E.1.4
    • Oracle Label Security 10.1, 10.4
    • recording policy labels E.1.3
    • SA_AUDIT_ADMIN.AUDIT_LABEL_ENABLED function E.1.4
    • SA_AUDIT_ADMIN.AUDIT_LABEL procedure E.1.3
    • SA_AUDIT_ADMIN.CREATE_VIEW procedure E.1.5
    • SA_AUDIT_ADMIN.DROP_VIEW procedure E.1.6
    • SA_AUDIT_ADMIN.NOAUDIT_LABEL procedure E.1.8
    • SA_AUDIT_ADMIN package E.1.1
    • strategy 10.5.1
    • systemwide 10.2
    • types of 5.9.8
    • views E.1.5

B


C

  • CDB_OLS_STATUS data dictionary view 4.1.2
  • CDB_OLS_STATUS view F.1.2.15
  • CDBs
    • Oracle Label Security 1.8.2
  • CHAR_TO_LABEL function 6.3.1, 6.5.2, 6.5.6
  • CHECK_CONTROL option
  • CHECK_WRITE function E.8.4
  • child rows
  • Cloud Control login 5.9.1
  • COMPACCESS privilege 3.5.2.3
  • compartments
    • altering E.2.2
    • creating E.2.6
    • definition 2.3.3, 5.3.4
    • deleting E.2.9
    • example 2.3.3, 5.3.4
    • finding F.1.2.28
    • finding compartments user can read in session E.5.2
    • finding compartments user can write to in session E.5.3
    • finding user information F.1.2.2
    • SA_COMPONENTS.ALTER_COMPARTMENT procedure E.2.2
    • SA_COMPONENTS.CREATE_COMPARTMENT procedure E.2.6
    • SA_COMPONENTS.DROP_COMPARTMENT procedure E.2.9
    • SA_USER_ADMIN.ADD_COMPARTMENTS procedure E.7.2
    • SA_USER_ADMIN.ALTER_COMPARTMENTS E.7.4
    • SA_USER_ADMIN.DROP_COMPARTMENTS procedure E.7.8
    • SA_USER_ADMIN.SET_COMPARTMENTS procedure E.7.11
    • SA_USER_ADMIN package E.7.1
    • setting authorizations 3.3.1.2, 5.4.4
  • components
    • SA_COMPONENT package E.2.1
    • SA_USER_ADMIN.DROP_ALL_COMPARTMENTS procedure E.7.6
  • CON C.4.1
  • configuration of Oracle Label security
  • connection parameters C.4.1
  • CREATE_GROUP procedure
  • CREATE_POLICY procedure
  • CREATE FUNCTION statement 9.4.1
  • CREATE PACKAGE BODY statement 9.4.1
  • CREATE PACKAGE statement 9.4.1
  • CREATE PROCEDURE statement 9.4.1
  • CREATE TABLE AS SELECT statement F.2
  • creating databases 12.5.1

D


E


F


G


H


I


L


M


N


O

  • object privileges
    • and Oracle Label Security privileges 3.5.4
    • and trusted stored program units 3.5.6, 9.2
  • OCI_ATTR_APPCTX_LIST B.3.2
  • OCI_ATTR_APPCTX_SIZE B.3.2
  • OCIAttrSet B.3.1, B.3.2
  • OCI interface B.3.1
  • OCIParamGet B.3.2
  • OLS_DOMINATED_BY function B.1.3.5
  • OLS_DOMINATES function B.1.3.2
  • OLS_GLBD function 6.4.4.2
  • OLS_GREATEST_LBOUND function 6.4.4.2
  • OLS_LABEL_DOMINATES function
  • OLS_LEAST_UBOUND function 6.4.4.1
  • OLS_LUBD function 6.4.4.1
  • OLS_STRICTLY_DOMINATED_BY function B.1.3.6
  • OLS_STRICTLY_DOMINATES function B.1.3.4
  • OptionsA C.4.2
  • Oracle Database Vault
    • using OLS_LABEL_DOMINATES function with B.1.3.3
  • Oracle Data Redaction
    • using OLS_LABEL_DOMINATES function with B.1.3.3
  • Oracle Enterprise Manager
    • administering labels 2.6
  • Oracle Internet Directory
    • configuring OLS after switchover to standby database 7.11.5
    • integration with OLS 1.8.1
    • OID with Oracle Data Guard 7.11.5
    • Oracle Label Security
      • about 7.1
      • administrator duties in 7.9
      • bootstrapping databases 7.10
      • configuring, about 7.2.1
      • configuring, permission for 7.2.2
      • configuring, steps 7.2.3
      • integrated capabilities of 7.5
      • PL/SQL procedures for policy administrators 7.14
      • policy attributes in 7.6
      • profiles, about 7.4
      • provisioning profiles, about 7.11.2
      • provisioning profiles, changing database connection information 7.11.4
      • provisioning profiles, managing 7.11.3
      • removing OID-enabled OLS from database 7.3
      • restrictions on new data label creation 7.8
      • security roles and permitted actions 7.12.1
      • subscribing policies in 7.7
      • superseded PL/SQL statements 7.13
      • synchronizing database with OID 7.11.1
      • un-registering database 7.2.4
  • Oracle Label Security
    • about 1.1
    • benefits 1.2
    • checking if registered and enabled 4.1.2
    • DBA_OLS_STATUS data dictionary view 4.1.2
    • privileges required to use 1.3
    • registering 4.1.1
  • Oracle Label Security (OLS)
    • integration with Oracle Internet Directory 1.8.1
  • Oracle Label Security data dictionary views
  • Oracle Label Security profiles 7.4
  • ORDER BY clause 6.4.2

P

  • packages
  • partitioning 6.1.2.3, 12.4.4
  • PDBs
    • Oracle Label Security 1.8.2
  • performance, Oracle Label Security
  • PL/SQL
    • recreating labels for import 12.2.2.2
    • SA_UTL package 9.5, E.8.1
    • trusted stored program units 9.1
  • pluggable databases
    • See: PDBs
  • policies
  • policies, schema
    • altering E.4.2
    • applying E.4.3
    • deleting E.4.11
    • disabling E.4.5
    • enabling E.4.7
    • SA_POLICY_ADMIN.ALTER_SCHEMA_POLICY procedure E.4.2
    • SA_POLICY_ADMIN.APPLY_SCHEMA_POLICY procedure E.4.3
    • SA_POLICY_ADMIN.ENABLE_SCHEMA_POLICY policy E.4.7
    • SA_POLICY_ADMIN.REMOVE_SCHEMA_POLICY procedure E.4.11
  • policies, schema, disabling
    • SA_POLICY_ADMIN.DISABLE_SCHEMA_POLICY procedure E.4.5
  • policies, table
    • applying E.4.4
    • deleting E.4.12
    • disabling E.4.6
    • enabling E.4.8
    • SA_POLICY_ADMIN.APPLY_TABLE_POLICY procedure E.4.4
    • SA_POLICY_ADMIN.DISABLE_TABLE_POLICY procedure E.4.6
    • SA_POLICY_ADMIN.ENABLE_TABLE_POLICY procedure E.4.8
    • SA_POLICY_ADMIN.REMOVE_TABLE_POLICY procedure E.4.12
  • policy_DBA role 2.2, E.3.1, E.7.18
    • about 1.4
    • auditing policy_DBA role users E.1.2
    • how to use 1.4
    • required for Data Pump import operations 12.2.2.1.2
    • required for label management E.3.1
    • required for Oracle Label Security auditing E.1.1
    • required for SA_USER_ADMIN.SET_PROG_PRIVS procedure E.7.15
    • required for SA_USER_ADMIN.SET_USER_PRIVS procedure E.7.18
  • policy label column
  • policy label containers
  • policy management
    • altering policies E.6.2
    • creating policies E.6.3
    • deleting policies E.6.5
    • disabling policies E.6.4
    • enabling policies E.6.6
    • SA_SYSDBA.ALTER_POLICY procedure E.6.2
    • SA_SYSDBA.CREATE_POLICY procedure E.6.3
    • SA_SYSDBA.DISABLE_POLICY procedure E.6.4
    • SA_SYSDBA.DROP_POLICY policy E.6.5
    • SA_SYSDBA.ENABLE_POLICY procedure E.6.6
    • SA_SYSDBA package E.6.1
  • predicates
  • privileges
  • PROFILE_ACCESS privilege 3.5.2.4
  • program units
    • finding policy privileges for F.1.2.8
  • propagated D.1

R


S

  • SA_AUDIT_ADMIN
    • procedures, listed E.1.1
  • SA_AUDIT_ADMIN.AUDIT_LABEL_ENABLED procedure E.1.4
  • SA_AUDIT_ADMIN.AUDIT_LABEL procedure E.1.3
  • SA_AUDIT_ADMIN.AUDIT procedure E.1.2
  • SA_AUDIT_ADMIN.CREATE_VIEW procedure E.1.5
  • SA_AUDIT_ADMIN.DROP_VIEW procedure E.1.6
  • SA_AUDIT_ADMIN.NOAUDIT_LABEL procedure E.1.8
  • SA_AUDIT_ADMIN.NOAUDIT procedure E.1.7
  • SA_AUDIT_ADMIN PL/SQL package
  • SA_COMPONENTS
    • procedures, listed E.2.1
  • SA_COMPONENTS.ALTER_COMPARTMENT procedure E.2.2
  • SA_COMPONENTS.ALTER_GROUP_PARENT procedure E.2.4
  • SA_COMPONENTS.ALTER_GROUP procedure E.2.3
  • SA_COMPONENTS.ALTER_LEVEL procedure E.2.5
  • SA_COMPONENTS.CREATE_COMPARTMENT procedure E.2.6
  • SA_COMPONENTS.CREATE_GROUP procedure E.2.7
  • SA_COMPONENTS.CREATE_LEVEL procedure E.2.8
  • SA_COMPONENTS.DROP_COMPARTMENT procedure E.2.9
  • SA_COMPONENTS.DROP_GROUP procedure E.2.10
  • SA_COMPONENTS.DROP_LEVEL procedure E.2.11
  • SA_COMPONENTS package E.2.1
  • SA_COMPONENTS PL/SQL package
  • SA_LABEL_ADMIN
    • procedures, listed E.3.1
  • SA_LABEL_ADMIN.ALTER_LABEL procedure E.3.2
  • SA_LABEL_ADMIN.CREATE_LABEL procedure E.3.3
  • SA_LABEL_ADMIN.DROP_LABEL procedure E.3.4
  • SA_LABEL_ADMIN PL/SQL package
  • SA_POLICY_ADMIN
    • procedures, listed E.4.1
  • SA_POLICY_ADMIN.ALTER_SCHEMA_POLICY procedure E.4.2
  • SA_POLICY_ADMIN.APPLY_SCHEMA_POLICY procedure E.4.3
  • SA_POLICY_ADMIN.APPLY_TABLE_POLICY procedure E.4.4
  • SA_POLICY_ADMIN.DISABLE_SCHEMA_POLICY procedure E.4.5
  • SA_POLICY_ADMIN.DISABLE_TABLE_POLICY procedure E.4.6
  • SA_POLICY_ADMIN.ENABLE_SCHEMA_POLICY procedure E.4.7
  • SA_POLICY_ADMIN.ENABLE_TABLE_POLICY procedure E.4.8
  • SA_POLICY_ADMIN.POLICY_SUBSCRIBE procedure E.4.9
  • SA_POLICY_ADMIN.POLICY_UNSUBSCRIBE procedure E.4.10
  • SA_POLICY_ADMIN.REMOVE_SCHEMA_POLICY procedure E.4.11
  • SA_POLICY_ADMIN.REMOVE_TABLE_POLICY procedure E.4.12
  • SA_POLICY_ADMIN PL/SQL package
  • SA_SESSION
    • procedures and functions, listed E.5.1
  • SA_SESSION.COMP_READ function E.5.2
  • SA_SESSION.COMP_WRITE function E.5.3
  • SA_SESSION.GROUP_READ function E.5.4
  • SA_SESSION.GROUP_WRITE function E.5.5
  • SA_SESSION.LABEL function E.5.6
  • SA_SESSION.MAX_LEVEL function E.5.7
  • SA_SESSION.MAX_READ_LABEL function E.5.8
  • SA_SESSION.MAX_WRITE_LABEL function E.5.9
  • SA_SESSION.MIN_LEVEL function E.5.10
  • SA_SESSION.MIN_WRITE_LABEL function E.5.11
  • SA_SESSION.PRIVS function E.5.12
  • SA_SESSION.RESTORE_DEFAULT_LABELS procedure E.5.13
  • SA_SESSION.ROW_LABEL function E.5.14
  • SA_SESSION.SA_USER_NAME function E.5.16
  • SA_SESSION.SAVE_DEFAULT_LABELS procedure E.5.17
  • SA_SESSION.SET_ACCESS_PROFILE procedure E.5.16, E.5.18
  • SA_SESSION.SET_LABEL procedure E.5.15
    • and SA_SESSION.RESTORE_DEFAULT_LABELS E.5.13
  • SA_SESSION.SET_ROW_LABEL procedure E.5.19
  • SA_SESSION PL/SQL package
  • SA_SYSDBA
    • procedures, listed E.6.1
  • SA_SYSDBA.ALTER_POLICY procedure E.6.2
  • SA_SYSDBA.CREATE_POLICY procedure E.6.3
  • SA_SYSDBA.DISABLE_POLICY procedure E.6.4
  • SA_SYSDBA.DROP_POLICY procedure E.6.5
  • SA_SYSDBA.ENABLE_POLICY procedure E.6.6
  • SA_SYSDBA PL/SQL package
  • SA_USER_ADMIN.ADD_COMPARTMENTS procedure E.7.2
  • SA_USER_ADMIN.ADD_GROUPS procedure E.7.3
  • SA_USER_ADMIN.ALTER_COMPARTMENTS procedure E.7.4
  • SA_USER_ADMIN.ALTER_GROUPS procedure E.7.5
  • SA_USER_ADMIN.DROP_ALL_COMPARTMENTS procedure E.7.6
  • SA_USER_ADMIN.DROP_ALL_GROUPS procedure E.7.7
  • SA_USER_ADMIN.DROP_COMPARTMENTS procedure E.7.8
  • SA_USER_ADMIN.DROP_GROUPS procedure E.7.9
  • SA_USER_ADMIN.DROP_USER_ACCESS procedure E.7.10
  • SA_USER_ADMIN.SET_COMPARTMENTS procedure E.7.11
  • SA_USER_ADMIN.SET_DEFAULT_LABEL procedure E.7.12
  • SA_USER_ADMIN.SET_GROUPS procedure E.7.13
  • SA_USER_ADMIN.SET_LEVELS procedure E.7.14
  • SA_USER_ADMIN.SET_ROW_LABEL procedure E.7.16
  • SA_USER_ADMIN.SET_USER_LABELS procedure E.7.17
  • SA_USER_ADMIN.SET_USER_PRIVS procedure E.7.18
  • SA_USER_ADMIN package
    • administering stored program units E.7.15
    • overview 2.2
    • procedures, listed E.7.1
  • SA_USER_ADMIN PL/SQL package
  • SA_UTL.CHECK_LABEL_CHANGE function E.8.2
  • SA_UTL.CHECK_READ function E.8.3
  • SA_UTL.CHECK_WRITE function E.8.4
  • SA_UTL.DATA_LABEL function E.8.5
  • SA_UTL.GREATEST_LBOUND function E.8.6
  • SA_UTL.LEAST_UBOUND function E.8.7
  • SA_UTL.NUMERIC_LABEL function E.8.8
  • SA_UTL.NUMERIC_ROW_LABEL function E.8.9
  • SA_UTL.SET_LABEL procedure E.8.10
  • SA_UTL.SET_ROW_LABEL procedure E.8.11
  • SA_UTL package
    • dominance functions B.1.3.7
    • overview 9.5
    • procedures and functions, listed E.8.1
  • SA_UTL PL/SQL package
  • schemas
    • applying policies to 8.1.9, E.6.2
    • default policy options E.6.3
    • restrictions on shared F.2
  • session labels
  • sessions
    • compartments readable by user E.5.2
    • compartments writeable by user E.5.3
    • finding current OLS user E.5.16
    • finding row label E.5.14
    • finding security attributes for F.1.2.34
    • finding session label number E.8.8
    • finding session privileges E.5.12
    • SA_SESSION.COMP_READ function E.5.2
    • SA_SESSION.COMP_WRITE function E.5.3
    • SA_SESSION.GROUP_READ function E.5.4
    • SA_SESSION.GROUP_WRITE function E.5.5
    • SA_SESSION.LABEL function E.5.6
    • SA_SESSION.MAX_LEVEL function E.5.7
    • SA_SESSION.MAX_READ_LABEL function E.5.8
    • SA_SESSION.MAX_WRITE_LABEL function E.5.9
    • SA_SESSION.MIN_LEVEL function E.5.10
    • SA_SESSION.MIN_WRITE_LABEL function E.5.11
    • SA_SESSION.PRIVS E.5.12
    • SA_SESSION.RESTORE_DEFAULT_LABELS procedure E.5.13
    • SA_SESSION.ROW_LABEL function E.5.14
    • SA_SESSION.SA_USER_NAME function E.5.16
    • SA_SESSION.SAVE_DEFAULT_LABELS procedure E.5.17
    • SA_SESSION.SET_ACCESS_PROFILE procedure E.5.18
    • SA_SESSION.SET_LABEL procedure E.5.15
    • SA_SESSION package E.5.1
    • SA_USER_ADMIN.SET_COMPARTMENTS procedure E.7.11
    • SA_USER_ADMIN.SET_DEFAULT_LABEL procedure E.7.12
    • SA_USER_ADMIN.SET_LEVELS procedure E.7.14
    • SA_UTL.SET_LABEL procedure E.8.10
    • SA_UTL.SET_ROW_LABEL procedure E.8.11
    • saving default session label E.5.17
    • setting label for E.8.10
    • setting OLS privileges for user E.5.18
    • setting row label for E.8.11
  • SET_ACCESS_PROFILE procedure F.2
  • SET_DEFAULT_LABEL procedure
  • SET_GROUPS procedure
  • SET_LABEL procedure
  • SET_PROG_PRIVS function E.7.15
  • SET_ROW_LABEL procedure 13.7.2.2, 13.7.2.3
  • SET_USER_LABELS procedure
  • setting label for database session E.8.10
  • shared schema restrictions F.2
  • SQL*Loader 12.3
  • STRICTLY_DOMINATED_BY function B.1.3.10
  • STRICTLY_DOMINATES function B.1.3.8
  • SYS_CONTEXT
  • SYS account
  • SYSDBA privilege 10.2
  • system privileges 3.5.4, 3.5.5, 3.5.6

T

  • table rows
    • checking if user can read E.8.3
    • checking if user can write to E.8.4
    • SA_UTL.CHECK_READ function E.8.3
    • SA_UTL.CHECK_WRITE function E.8.4
  • TO_DATA_LABEL function 6.5.6, E.3.3
  • TO_LBAC_DATA_LABEL function 8.2.2
  • TO_LBAC_DATA_LABEL function, example of using E.8.10
  • triggers 8.2.2
  • trusted program units
  • trusted stored program units

U


V


W