Effective Oracle Database 10g Security by Design 1st Edition By David Knox
$30.00
Secure checkout
Instant digital download
PDF document
Document details
- Pages
- 490
- File size
- 2.95 MB
- Format
- Digital PDF
- Course
- Computer Applications
- Category
- eBook[PDF]
Sign in or create a free account to continue. Your purchase will be saved in My Downloads.
About this ebook
The Effective Oracle Database 10g Security by Design (1st Edition) by David Knox covers the complete database security cycle, moving from introductory vulnerability assessment to fine-grained access control, encryption, and tracking. Published by McGraw-Hill/Oracle Press, the book focuses heavily on a "secure by design" philosophy using real-world scenarios. [1, 2]
The primary topics and technologies covered in the book include:
1. Fundamentals & Strategy
- Vulnerability Assessment: Developing high-level security policies and identifying potential security gaps in database configurations.
- General Security Best Practices: Foundational strategies for database hardening and establishing an enterprise security framework. [1, 2]
2. Identification, Authentication, & Identity Management
- Preserving User Identity: Deep dive into identity preservation across multi-tier environments, specifically evaluating JDBC connection pools, proxy authentication, and client identifiers.
- Centralized User Management: Managing users via centralized enterprise directories (such as LDAP) without compromising data security.
- Oracle Identity Management Infrastructure: Utilizing the broader identity framework to unify application and database tiers. [1]
3. Authorization & Access Control
- Secure Application Roles: Implementing database roles that are dynamically enabled only when specific application parameters or conditions are met. [1]
- Privilege Validation: Using custom views and administrative scripts to audit and validate user privileges. [1]
- Fine-Grained Access Control (FGAC): Using database views to enforce structural row-level and column-level restrictions. [1]
- Virtual Private Database (VPD) & Oracle Label Security (OLS): Enforcing "need-to-know" data privacy natively within the kernel using context-sensitive policies. [1]
4. Data Protection & Accountability
- Data Element Encryption: Protecting data at rest using the then-new
DBMS_CRYPTOpackage introduced in Oracle 10g. - Fine-Grained Auditing (FGA): Implementing precision event tracking and audit trails to guarantee total user accountability without dragging down system performance. [1]
File included
tmpphpFQs8nt
2.95 MB