Provisioning Audit Policies
Oracle AI Database provides a variety of ways for you to audit activities.
-
Getting Started with Auditing
Effective auditing requires that audit policies be selective and focused. This ensures that the audit records generated are what is needed to support forensic analysis, and compliance, without generating unnecessary audit records. -
About Audit Policies
An audit policy is a named group of audit settings that enable you to audit a particular aspect of user behavior in the database. -
Activities That Are Mandatorily Audited
Certain security sensitive database activities are always audited and such audit configurations cannot be disabled. -
Auditing Activities with the Predefined Unified Audit Policies
Oracle Database provides predefined unified audit policies that cover commonly used security-relevant audit settings. -
Steps to Provision Unified Audit Policies
Apart from mandatorily audited activities and predefined unified audit policies enabled by default in the Oracle database, you may need to provision additional unified audit policies based on your security and compliance needs. -
Common Audit Configurations Across All PDBs
A common audit configuration is visible and enforced across all PDBs. -
General Audit Data Dictionary Views
Oracle Database provides different types of data dictionary and dynamic views for use with unified auditing.
Getting Started with Auditing
Effective auditing requires that audit policies be selective and focused. This ensures that the audit records generated are what is needed to support forensic analysis, and compliance, without generating unnecessary audit records.
The most common activities to audit includes but are not limited to the following
-
Failed logins
-
Any login from outside of the application or monitoring tools
-
Data Definition Language – creating, dropping, or changing database objects
-
Data Control Language – especially create user, alter user, privilege and role grants
-
Oracle Data Pump import operations
-
Any Oracle Database Vault activity or rule violation
-
Any
SYSDBAor database administrator activity
The top three tips to get started on auditing activities with Oracle Database with unified auditing are as follows:
-
Do not duplicate mandatory audit configurations which are always on in the Oracle database.
-
Use the predefined unified audit policies provided in Oracle Database, Oracle Data Safe, or Oracle Audit Vault and Database Firewall (AVDF).
-
Create custom audit policies (unified audit or fine-grained) for specialized needs.
You can fine-tune unified audit policies with conditions and enforced on specific users to reduce audit volume. You may want to use conditional enablement features for use cases, such as the following:
-
Monitor access to sensitive data outside the trusted application path to focus only on the activity that matters.
-
Monitor any activity from ad-hoc or power users who typically have access to query the data outside the trusted application paths.
Related Topics
About Audit Policies
An audit policy is a named group of audit settings that enable you to audit a particular aspect of user behavior in the database.
You can create audit policies that monitor a wide range of activities, such as the following:
-
User accounts (including administrative users who log in with the
SYSDBAadministrative privilege), roles, and privileges -
Object actions, such as dropping a table or a running a procedure
-
Application context values
-
Activities from other Oracle Database products, such as Oracle Database Real Application Security, Oracle Recovery Manager, or Oracle Data Pump.
Oracle Database provides three ways for you to create audit policies:
-
Use predefined unified audit policies for auditing the most common security relevant activities. The predefined audit policies enable you to follow certain industry standards, such as the Center for Internet Security Recommendations or the Security Technical Implementation Guide standards. Predefined policies are also available for common audit tasks such as failed logins, and for other Oracle products, such as Oracle Database Real Application Security and Oracle Database Vault. The predefined audit policies should be sufficient for most auditing needs, but if they are not, then you can create custom audit policies or fine-grained audit policies.
-
Create custom unified audit policies for more specific activities. Custom unified audit policies enable you to audit a wide range of activities, such as auditing the use of roles or actions performed on objects like tables. You use the
CREATE AUDIT POLICYstatement to create the unified audit policy, and theAUDITstatement to enable it. TheCREATE AUDIT POLICYsyntax is flexible enough for you to build in conditions, for example, or audit application context values. -
Create fine-grained audit policies for more granular audit needs. Fine-grained audit policies are not unified audit policies; you use the
DBMS_FGAPL/SQL package to create a fine-grained audit policy. Fine-grained audit policies enable you to include conditions and event handlers. For example, you can send alerts to an administrator if a user violates the audit policy. You can also audit specific rows of a table based on the value in a certain column with fine-grained audit.
Activities That Are Mandatorily Audited
Certain security sensitive database activities are always audited and such audit configurations cannot be disabled.
Activities that are always audited include but are not limited to the following:
-
Activities of administrative users such as
SYSDBA,SYSBACKUP, andSYSKMwhen the database is down is always audited. -
Any DDL or DML attempts on
UNIFIED_AUDIT_TRAILor the underlying dictionary tables inAUDSYSschema is always audited. These operations are not permitted by design. The unified audit trail resides in a specialized table in theAUDSYSschema that only allowsINSERTactivity.
Mandatorily audited activities will have audit policy by name ORA$MANDATORY in the UNIFIED_AUDIT_POLICIES column of the UNIFIED_AUDIT_TRAIL data dictionary view. The ORA$MANDATORY is always listed first in this column, if there are other unified audit policies that are tracking mandatorily audited activities. The SYSTEM_PRIVILEGE_USED column shows the type of administrative privilege that was used for the activity.
The following activities are mandatorily audited in Oracle Database:
Non-Audit-Related Activities
-
SQL Firewall administrative actions
-
ORADEBUGutility
Audit-Related Activities
-
CREATE AUDIT POLICY -
ALTER AUDIT POLICY -
DROP AUDIT POLICY -
AUDIT -
NOAUDIT -
EXECUTEof theDBMS_FGAPL/SQL package -
EXECUTEof theDBMS_AUDIT_MGMTPL/SQL package -
ALTER TABLEattempts on theAUDSYSaudit trail table (remember that this table cannot be altered) -
Top level statements by the administrative users
SYS,SYSDBA,SYSOPER,SYSASM,SYSBACKUP,SYSDG, andSYSKM, until the database opens. -
All user-issued DML statements on the
SYS.AUD$andSYS.FGA_LOG$dictionary tables -
Any attempts to modify the data or metadata of the unified audit internal table.
SELECTstatements on this table are not audited by default or mandatorily. -
All configuration changes that are made to Oracle Database Vault
Mandatorily Audited Access to Sensitive Columns in the Oracle Optimizer Dictionary Tables
Be aware that internal access to these table columns by the DBMS_STATS package does not generate mandatory audit records. You can use the ORA$DICTIONARY_SENS_COL_ACCESS predefined audit policy to audit these tables. The optimizer dictionary tables are as follows:
| Optimizer Dictionary Table | Columns |
|---|---|
SYS.HIST_HEAD$ |
minimum, maximum, lowval, hival |
SYS.HISTGRM$ |
endpoint, epvalue_raw |
SYS.WRI$_OPSTAT_HISTGRM_HISTORY |
endpoint, epvalue_raw |
SYS.WRI$_OPTSTAT_HISTHEAD_HISTORY |
minimum, maximum, lowval, hival |
Mandatorily Audited Operations on Blockchain and Immutable Tables
-
CREATE TABLE -
DROP TABLE -
Failed
ALTER TABLEoperations -
Failed
DELETEoperations -
Failed
FLASHBACK TABLEoperations -
Failed
RENAMEoperations -
Failed
TRUNCATE TABLEoperations -
Failed
UPDATEoperations
Related Topics