Provisioning Audit Policies

Oracle AI Database provides a variety of ways for you to audit activities.

Getting Started with Auditing

Effective auditing requires that audit policies be selective and focused. This ensures that the audit records generated are what is needed to support forensic analysis, and compliance, without generating unnecessary audit records.

The most common activities to audit includes but are not limited to the following

The top three tips to get started on auditing activities with Oracle Database with unified auditing are as follows:

  1. Do not duplicate mandatory audit configurations which are always on in the Oracle database.

  2. Use the predefined unified audit policies provided in Oracle Database, Oracle Data Safe, or Oracle Audit Vault and Database Firewall (AVDF).

  3. Create custom audit policies (unified audit or fine-grained) for specialized needs.

You can fine-tune unified audit policies with conditions and enforced on specific users to reduce audit volume. You may want to use conditional enablement features for use cases, such as the following:

Related Topics

About Audit Policies

An audit policy is a named group of audit settings that enable you to audit a particular aspect of user behavior in the database.

You can create audit policies that monitor a wide range of activities, such as the following:

Oracle Database provides three ways for you to create audit policies:

Activities That Are Mandatorily Audited

Certain security sensitive database activities are always audited and such audit configurations cannot be disabled.

Activities that are always audited include but are not limited to the following:

Mandatorily audited activities will have audit policy by name ORA$MANDATORY in the UNIFIED_AUDIT_POLICIES column of the UNIFIED_AUDIT_TRAIL data dictionary view. The ORA$MANDATORY is always listed first in this column, if there are other unified audit policies that are tracking mandatorily audited activities. The SYSTEM_PRIVILEGE_USED column shows the type of administrative privilege that was used for the activity.

The following activities are mandatorily audited in Oracle Database:

Non-Audit-Related Activities

Audit-Related Activities

Mandatorily Audited Access to Sensitive Columns in the Oracle Optimizer Dictionary Tables

Be aware that internal access to these table columns by the DBMS_STATS package does not generate mandatory audit records. You can use the ORA$DICTIONARY_SENS_COL_ACCESS predefined audit policy to audit these tables. The optimizer dictionary tables are as follows:

Optimizer Dictionary Table Columns
SYS.HIST_HEAD$ minimum, maximum, lowval, hival
SYS.HISTGRM$ endpoint, epvalue_raw
SYS.WRI$_OPSTAT_HISTGRM_HISTORY endpoint, epvalue_raw
SYS.WRI$_OPTSTAT_HISTHEAD_HISTORY minimum, maximum, lowval, hival

Mandatorily Audited Operations on Blockchain and Immutable Tables

Related Topics