SlideShare a Scribd company logo
Session 319:
Security Compliance using
Oracle Enterprise Manager 12c

                       Bobby Curtis, MBA
                       Solution Architect
                       BIAS Corporation
                       April 2013
•    Founded in 2000
             •    Oracle Platinum Partner with 20+ specializations
             •    Distinguished Oracle Leader
                      –  Technology Momentum
                      –  Portal Blazer Award
                      –  Titan Award – Red Stack + HW Momentum
                      –  Excellence in Innovation
             •    Management Team is Ex-Oracle
             •    Location(s): Atlanta, Washington D.C.,
                               Offshore – Hyderabad and Chennai, India
About BIAS




             •    Inc.500 fastest growing private company in the U.S. for the 3rd Time
             •    Voted Best Place to work in Atlanta for 2nd year
Bobby Curtis, MBA
                        •    Douglasville, Georgia (west side of Atlanta)
                        •    Solution Architect, BIAS Corp.
About Presenter


                        •    Implementation Specialist for Core Technologies
                        •    IOUG, ODTUG, & GOUSER
                        •    Using Oracle products since 2001
                        •    Previous Life: Military/Systems Administrator



                  Blog: http://www.dbasolved.com
                  Twitter: @curtisbl294
                  Email: bobby.curtis@biascorp.com
                              curtisbl@gmail.com
§  Compliance	
  
                 §  Customer	
  Story	
  -­‐	
  CCH	
  
                 §  Puzzle	
  Pieces	
  
Session Agenda



                 §  Configura8on	
  
                 §  Addi8onal	
  Informa8on	
  
                 §  Customer	
  Improvements	
  
                 §  Wrap-­‐Up	
  
Compliance
Compliance Management   What	
  is	
  compliance	
  management?	
  

                                              The	
  ability	
  to	
  evaluate	
  the	
  
                                              compliance	
  of	
  targets	
  and	
  
                                              systems	
  as	
  they	
  are	
  related	
  to	
  
                                              best	
  prac8ces	
  for	
  configura8on,	
  
                                              security,	
  and	
  storage.	
  
Compliance Overview   Compliance	
  solu8on	
  consists	
  of:	
  
What	
  do	
  these	
  numbers	
  	
  
                      have	
  to	
  do	
  with	
  security	
  compliance?	
  
Compliance Overview

                                                6	
   	
  	
  	
  	
  	
  	
  	
  Frameworks	
  
                                                 :0	
  
                                               50	
   	
  	
  	
  	
  	
  Standards	
  
                                                 :23	
  
                                                 :115	
  	
  	
  	
  Rules	
  
                                             1827	
  
Customer Story
Who	
  is…	
  
                        •  Leading	
  provider	
  of	
  Tax,	
  Accoun8ng	
  and	
  Audit	
  
                           Informa8on	
  SoUware	
  for	
  professionals	
  
                        •  Subsidiary	
  of	
  Wolters	
  Kluwer	
  Tax	
  &	
  Accoun8ng	
  
Customer Story



                        •  Based	
  in	
  Riverwoods,	
  Ill.,	
  office	
  in	
  Kennesaw,	
  GA.	
  

                        •  Largest	
  customer	
  is	
  Internal	
  Revenue	
  Service	
  (IRS)	
  

                        •  Booth	
  1318	
  
                 	
  
•  Reliable	
  monitoring	
  for	
  3	
  RAC	
  environments	
  

                 •  High	
  security	
  requirements	
  
Customer Story



                 •  Needed	
  to	
  enforce	
  compliance	
  

                 •  Annual	
  audits	
  are	
  8me	
  consuming	
  
Compliance Puzzle Pieces
There	
  are	
  three	
  pieces	
  to	
  the	
  compliance	
  
Puzzle Pieces, oh my…
                        puzzle.	
  	
  They	
  are	
  the	
  building	
  blocks	
  for	
  
                        compliance	
  and	
  are	
  hierarchical	
  structure.	
  

                                 1.  Frameworks	
  
                                 2.  Standards	
  
                                 3.  Rules	
  
                                       ü  Real-­‐Time	
  Facets*	
  
                                       ü  Templates*	
  
Puzzle Pieces : Framework   A	
  compliance	
  framework	
  is	
  a	
  hierarchical	
  structure	
  
                            where	
  any	
  node	
  can	
  be	
  mapped	
  to	
  one	
  or	
  more	
  
                            compliance	
  standards	
  and	
  compliance	
  standard	
  
                            rules.	
  
                                     2	
  Types	
  of	
  Frameworks:	
  
                                     	
  

                                     §  Oracle	
  Provided	
  
                                            §  Payment	
  Card	
  Industry	
  (PCI)	
  
                                            §  Generic	
  
                                     §  User-­‐Defined	
  
                                            §  Defined	
  to	
  sa8sfy	
  the	
  needs	
  of	
  your	
  organiza8on	
  
Puzzle Pieces : Standards   A	
  compliance	
  standard	
  is	
  a	
  collec8on	
  of	
  checks	
  or	
  
                            rules.	
  

                                 Standards-­‐Hierarchical	
  Structure:	
  
                                 	
  

                                 §  Compliance	
  Rules	
  
                                 §  Rule	
  Folders	
  
                                      §  Hierarchical	
  structure	
  the	
  constrains	
  compliance	
  rules	
  
                                 §  Compliance	
  Standards	
  
                                        §  Can	
  include	
  other	
  compliance	
  standards	
  
What	
  do	
  standards	
  do:	
  
Puzzle Pieces : Standards
                            	
  

                            §  Represent	
  Industry-­‐wide	
  standards,	
  per	
  target	
  
                            §  Used	
  as	
  reference	
  configura8on/cer8fied	
  configura8on	
  
                            §  Describe	
  best	
  prac8ces	
  for	
  enterprise	
  
                                                                               Security	
  Compliance	
  Standards	
  By	
  
                                                                                             Target	
  Type	
  
                                                                        Automa8c	
  Storage	
  Management	
  (ASM)	
      2	
  
                                                                        Cluster	
                                         1	
  
                                                                        Cluster	
  Database	
                             7	
  
                                                                        Database	
  Instance	
                            9	
  
                                                                        Host	
                                            2	
  
                                                                        Listener	
                                        2	
  
                                                                        Total	
                                          23	
  
A	
  compliance	
  rule	
  is	
  a	
  test	
  that	
  determines	
  if	
  
                        configura8on	
  data	
  change	
  affects	
  compliance.	
  	
  
                        Based	
  on	
  the	
  result,	
  the	
  compliance	
  score	
  is	
  
Puzzle Pieces : Rules

                        calculated.	
  
                                   3	
  Types	
  of	
  Rules:	
  
                                   §  Repository	
  Rules	
  
                                         §  Check	
  against	
  metrics	
  in	
  management	
  repository	
  
                                   §  Weblogic	
  Server	
  Signature	
  Rules	
  
                                         §  Describe	
  poten8al	
  problems	
  based	
  on	
  info	
  about	
  Weblogic	
  
                                             Server	
  and	
  environment	
  
                                   §  Real-­‐Time	
  Monitoring	
  
                                         §  Monitors	
  ac8ons	
  performed	
  by	
  users	
  on	
  targets	
  
Puzzle Pieces : Templates   Enable	
  security	
  compliance;	
  templates	
  have	
  to	
  be	
  
                            enabled.	
  
Evaluation…Understand
                                                       Number	
  of	
  targets	
  
                                                       evaluated	
  as	
  Cri8cal,	
  
                                                       Warning,	
  or	
  Compliant	
     Average	
  Score	
  for	
  Evalua8on	
  




                        Number	
  of	
  Cri8cal,	
                                              Compliance	
  Score	
  Ra9ngs	
  
                        Warning,	
  or	
  Minor	
  Warning	
                                 Cri9cal	
                        <	
  60	
  
                        viola8ons	
  across	
  all	
  targets	
                             Warning	
                         <	
  80	
  

                                                                                           Compliant	
                        >	
  80	
  	
  
Compliance	
  Summary	
  &	
  Details	
  
                     	
  

                            §  Enterprise	
  Summary	
  
Evaluation… Review

                            §  Compliance	
  Dashboard	
  
Configure the Puzzle Pieces
Configure: Library




                     3	
     2	
     1	
     N/A	
  
Configure: Rules
Configure: Rules
Configure: Standards
Compliance	
  Standards	
  are:	
  
                       	
  

                       §  Hierarchical	
  in	
  nature	
  
                       §  Must	
  have	
  at	
  least	
  1	
  rule	
  
Configure: Standards

                       	
  

                              Adding	
  Rules/Standards	
  is	
  
                              simple!	
  
                              	
  

                                     Right	
  click-­‐>Edit-­‐>Add	
  
Configure: Framework



                       §  Top	
  most	
  level	
  of	
  compliance	
  
                       §  Only	
  standards	
  can	
  be	
  added	
  
                       §  Standards	
  in	
  subgroups	
  
§  Oracle	
  Security	
  Template	
  
          §  Immediately	
  available	
  
              (some	
  delay)	
  
Results
Results
Dashboard	
  Consists	
  of:	
  
          	
  

          §  Compliance	
  Framework	
  
              Summary	
  
          §  Compliance	
  Summary	
  
          §  Least	
  Compliant	
  Generic	
  
              Systems	
  
Results




          §  Most	
  Recently	
  Discovered	
  
              Unmanaged	
  Hosts	
  
          §  Least	
  Compliant	
  Targets	
  
Additional Information
Compliance	
  from	
  the	
  command	
  line:	
  
                §    export_compliance_group	
  
                §    export_compliance_standard_rule	
  	
  
                §    export_standard	
  	
  	
  	
  	
  	
  	
  
                §    import_compliance_object	
  	
  	
  
EMCLI Options
Views	
  for	
  Compliance	
  (SYSMAN)	
  
                         §    MGMT$COMPLIANCE_STANDARD_GROUP	
  
                         §    MGMT$COMPLIANCE_STANDARD	
  
                         §    MGMT$COMPLIANCE_STANDARD_RULE	
  
                         §    MGMT$COMPLIANCE_SUMMARY	
  
SQL Options



                         §    MGMT$COMPLIANT_TARGETS	
  
                         §    MGMT$COMPLIANCE_TREND	
  
                         §    MGMT$COMPOSITE_CS_EVAL_SUMMARY	
  
              Oracle	
  Enterprise	
  Manager	
  Cloud	
  Control	
  Extensibility	
  Programmers	
  Guide	
  
              Chapter	
  18	
  	
  	
  
To	
  use	
  compliance	
  standards:	
  
                                             §    CREATE_COMPLIANCE_ENTITY	
  
Privileges & Roles

                                             §    FULL_ANY_COMPLIANCE_ENTITY	
  
                                             §    VIEW_ANY_COMPLIANCE_FWK	
  
                                             §    MANAGE_TARGET_COMPLIANCE	
  
                                             §    VIEW	
  
                                             §    EM_COMPLIANCE_DESIGNER	
  (ROLE)	
  
                                             §    EM_COMPLIANCE_OFFICE	
  (ROLE)	
  
Customer Story.. Improvement?
§  Able	
  to	
  monitor	
  in	
  all	
  environments	
  
                 §  Has	
  a	
  easier	
  and	
  measurable	
  way	
  of	
  enforcing	
  
                     compliance	
  across	
  environments	
  
Customer Story


                 	
  

                 §  Expected	
  to	
  reduce	
  annual	
  audit	
  8mes	
  by	
  
                     40%-­‐50%	
  
§  Brief	
  customer	
  story	
  
          §  Talked	
  about	
  compliance	
  and	
  its	
  importance	
  
          §  Implemented	
  security	
  aspects	
  of	
  the	
  compliance	
  
              model	
  and	
  how	
  to	
  review	
  results	
  
          §  Discussed	
  addi8onal	
  op8ons	
  for	
  compliance	
  
Wrap Up




          §  Results	
  of	
  customer	
  implemen8ng	
  compliance	
  
Discussion & Questions
Thank You for Attending

    Blog: http://www.dbasolved.com
    Twitter: @curtisbl294
    Email: bobby.curtis@biascorp.com
                curtisbl@gmail.com




      hrp://www.biascorp.com	
  
      	
  

More Related Content

What's hot

Oracle GoldenGate 12c CDR Presentation for ECO
Oracle GoldenGate 12c CDR Presentation for ECOOracle GoldenGate 12c CDR Presentation for ECO
Oracle GoldenGate 12c CDR Presentation for ECO
Bobby Curtis
 
Enable GoldenGate Monitoring with OEM 12c/JAgent
Enable GoldenGate Monitoring with OEM 12c/JAgentEnable GoldenGate Monitoring with OEM 12c/JAgent
Enable GoldenGate Monitoring with OEM 12c/JAgent
Bobby Curtis
 
Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...
Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...
Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...
Tammy Bednar
 
Understanding Oracle GoldenGate 12c
Understanding Oracle GoldenGate 12cUnderstanding Oracle GoldenGate 12c
Understanding Oracle GoldenGate 12c
IT Help Desk Inc
 
Oracle Database 19c - poslední z rodiny 12.2 a co přináší nového
Oracle Database 19c - poslední z rodiny 12.2 a co přináší novéhoOracle Database 19c - poslední z rodiny 12.2 a co přináší nového
Oracle Database 19c - poslední z rodiny 12.2 a co přináší nového
MarketingArrowECS_CZ
 
Oracle GoldenGate and Baseball - 5 Keys for Moving to the Cloud
Oracle GoldenGate and Baseball - 5 Keys for Moving to the CloudOracle GoldenGate and Baseball - 5 Keys for Moving to the Cloud
Oracle GoldenGate and Baseball - 5 Keys for Moving to the Cloud
Bobby Curtis
 
OEM12c, DB12c and You! - RMOUG TD2014 Edition
OEM12c, DB12c and You! - RMOUG TD2014 EditionOEM12c, DB12c and You! - RMOUG TD2014 Edition
OEM12c, DB12c and You! - RMOUG TD2014 Edition
Bobby Curtis
 
What’s New in Oracle Database 19c - Part 1
What’s New in Oracle Database 19c - Part 1What’s New in Oracle Database 19c - Part 1
What’s New in Oracle Database 19c - Part 1
Satishbabu Gunukula
 
Improve PostgreSQL replication with Oracle GoldenGate
Improve PostgreSQL replication with Oracle GoldenGateImprove PostgreSQL replication with Oracle GoldenGate
Improve PostgreSQL replication with Oracle GoldenGate
Bobby Curtis
 
ECO 2022 - OCI and HashiCorp Terraform
ECO 2022 - OCI and HashiCorp TerraformECO 2022 - OCI and HashiCorp Terraform
ECO 2022 - OCI and HashiCorp Terraform
Bobby Curtis
 
Zero Downtime Migration
Zero Downtime MigrationZero Downtime Migration
Zero Downtime Migration
Software Park Thailand
 
Oracle ZDM KamaleshRamasamy Sangam2020
Oracle ZDM KamaleshRamasamy Sangam2020Oracle ZDM KamaleshRamasamy Sangam2020
Oracle ZDM KamaleshRamasamy Sangam2020
Kamalesh Ramasamy
 
Spotlight private dns-oraclecloudservices
Spotlight private dns-oraclecloudservicesSpotlight private dns-oraclecloudservices
Spotlight private dns-oraclecloudservices
Tammy Bednar
 
Oracle GoldenGate 18c - REST API Examples
Oracle GoldenGate 18c - REST API ExamplesOracle GoldenGate 18c - REST API Examples
Oracle GoldenGate 18c - REST API Examples
Bobby Curtis
 
Oracle Fleet Patching and Provisioning Deep Dive Webcast Slides
Oracle Fleet Patching and Provisioning Deep Dive Webcast SlidesOracle Fleet Patching and Provisioning Deep Dive Webcast Slides
Oracle Fleet Patching and Provisioning Deep Dive Webcast Slides
Ludovico Caldara
 
Maa goldengate-rac-2007111
Maa goldengate-rac-2007111Maa goldengate-rac-2007111
Maa goldengate-rac-2007111
pablitosax
 
New availability features in oracle rac 12c release 2 anair ss
New availability features in oracle rac 12c release 2 anair   ssNew availability features in oracle rac 12c release 2 anair   ss
New availability features in oracle rac 12c release 2 anair ss
Anil Nair
 
Oracle RAC 19c: Best Practices and Secret Internals
Oracle RAC 19c: Best Practices and Secret InternalsOracle RAC 19c: Best Practices and Secret Internals
Oracle RAC 19c: Best Practices and Secret Internals
Anil Nair
 
Oracle Goldengate training by Vipin Mishra
Oracle Goldengate training by Vipin Mishra Oracle Goldengate training by Vipin Mishra
Oracle Goldengate training by Vipin Mishra
Vipin Mishra
 

What's hot (20)

Oracle GoldenGate 12c CDR Presentation for ECO
Oracle GoldenGate 12c CDR Presentation for ECOOracle GoldenGate 12c CDR Presentation for ECO
Oracle GoldenGate 12c CDR Presentation for ECO
 
Enable GoldenGate Monitoring with OEM 12c/JAgent
Enable GoldenGate Monitoring with OEM 12c/JAgentEnable GoldenGate Monitoring with OEM 12c/JAgent
Enable GoldenGate Monitoring with OEM 12c/JAgent
 
Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...
Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...
Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...
 
Understanding Oracle GoldenGate 12c
Understanding Oracle GoldenGate 12cUnderstanding Oracle GoldenGate 12c
Understanding Oracle GoldenGate 12c
 
Oracle Database 19c - poslední z rodiny 12.2 a co přináší nového
Oracle Database 19c - poslední z rodiny 12.2 a co přináší novéhoOracle Database 19c - poslední z rodiny 12.2 a co přináší nového
Oracle Database 19c - poslední z rodiny 12.2 a co přináší nového
 
Oracle GoldenGate and Baseball - 5 Keys for Moving to the Cloud
Oracle GoldenGate and Baseball - 5 Keys for Moving to the CloudOracle GoldenGate and Baseball - 5 Keys for Moving to the Cloud
Oracle GoldenGate and Baseball - 5 Keys for Moving to the Cloud
 
OEM12c, DB12c and You! - RMOUG TD2014 Edition
OEM12c, DB12c and You! - RMOUG TD2014 EditionOEM12c, DB12c and You! - RMOUG TD2014 Edition
OEM12c, DB12c and You! - RMOUG TD2014 Edition
 
What’s New in Oracle Database 19c - Part 1
What’s New in Oracle Database 19c - Part 1What’s New in Oracle Database 19c - Part 1
What’s New in Oracle Database 19c - Part 1
 
Improve PostgreSQL replication with Oracle GoldenGate
Improve PostgreSQL replication with Oracle GoldenGateImprove PostgreSQL replication with Oracle GoldenGate
Improve PostgreSQL replication with Oracle GoldenGate
 
ECO 2022 - OCI and HashiCorp Terraform
ECO 2022 - OCI and HashiCorp TerraformECO 2022 - OCI and HashiCorp Terraform
ECO 2022 - OCI and HashiCorp Terraform
 
Zero Downtime Migration
Zero Downtime MigrationZero Downtime Migration
Zero Downtime Migration
 
Oracle ZDM KamaleshRamasamy Sangam2020
Oracle ZDM KamaleshRamasamy Sangam2020Oracle ZDM KamaleshRamasamy Sangam2020
Oracle ZDM KamaleshRamasamy Sangam2020
 
Spotlight private dns-oraclecloudservices
Spotlight private dns-oraclecloudservicesSpotlight private dns-oraclecloudservices
Spotlight private dns-oraclecloudservices
 
Oracle GoldenGate 18c - REST API Examples
Oracle GoldenGate 18c - REST API ExamplesOracle GoldenGate 18c - REST API Examples
Oracle GoldenGate 18c - REST API Examples
 
Oracle Fleet Patching and Provisioning Deep Dive Webcast Slides
Oracle Fleet Patching and Provisioning Deep Dive Webcast SlidesOracle Fleet Patching and Provisioning Deep Dive Webcast Slides
Oracle Fleet Patching and Provisioning Deep Dive Webcast Slides
 
Maa goldengate-rac-2007111
Maa goldengate-rac-2007111Maa goldengate-rac-2007111
Maa goldengate-rac-2007111
 
Oracle dba
Oracle  dbaOracle  dba
Oracle dba
 
New availability features in oracle rac 12c release 2 anair ss
New availability features in oracle rac 12c release 2 anair   ssNew availability features in oracle rac 12c release 2 anair   ss
New availability features in oracle rac 12c release 2 anair ss
 
Oracle RAC 19c: Best Practices and Secret Internals
Oracle RAC 19c: Best Practices and Secret InternalsOracle RAC 19c: Best Practices and Secret Internals
Oracle RAC 19c: Best Practices and Secret Internals
 
Oracle Goldengate training by Vipin Mishra
Oracle Goldengate training by Vipin Mishra Oracle Goldengate training by Vipin Mishra
Oracle Goldengate training by Vipin Mishra
 

Viewers also liked

WAMIN0119 - MM Mar 2015 (002)
WAMIN0119 - MM Mar 2015 (002)WAMIN0119 - MM Mar 2015 (002)
WAMIN0119 - MM Mar 2015 (002)Alex Gallagher
 
最新oeko证书
最新oeko证书最新oeko证书
最新oeko证书Daidong Liu
 
Unidad 1 introducción
Unidad 1 introducciónUnidad 1 introducción
Unidad 1 introducción
Equidad Y Justicia Docente Contigo
 
ольга ринк презентация
ольга ринк   презентацияольга ринк   презентация
ольга ринк презентация
journalrubezh
 
Protecting Patient Privacy
Protecting Patient PrivacyProtecting Patient Privacy
Protecting Patient PrivacyLeigh Caudill
 
Atmcorp presentation
Atmcorp presentationAtmcorp presentation
Audizione FIRE al senato sui certificati bianchi
Audizione FIRE al senato sui certificati bianchiAudizione FIRE al senato sui certificati bianchi
Audizione FIRE al senato sui certificati bianchi
Dario Di Santo
 

Viewers also liked (12)

Jazz chant
Jazz chantJazz chant
Jazz chant
 
fang
fangfang
fang
 
WAMIN0119 - MM Mar 2015 (002)
WAMIN0119 - MM Mar 2015 (002)WAMIN0119 - MM Mar 2015 (002)
WAMIN0119 - MM Mar 2015 (002)
 
最新oeko证书
最新oeko证书最新oeko证书
最新oeko证书
 
Unidad 1 introducción
Unidad 1 introducciónUnidad 1 introducción
Unidad 1 introducción
 
ольга ринк презентация
ольга ринк   презентацияольга ринк   презентация
ольга ринк презентация
 
Elihouri logo f
Elihouri logo fElihouri logo f
Elihouri logo f
 
Protecting Patient Privacy
Protecting Patient PrivacyProtecting Patient Privacy
Protecting Patient Privacy
 
Atmcorp presentation
Atmcorp presentationAtmcorp presentation
Atmcorp presentation
 
Buy RETIN-A Online
Buy RETIN-A OnlineBuy RETIN-A Online
Buy RETIN-A Online
 
Audizione FIRE al senato sui certificati bianchi
Audizione FIRE al senato sui certificati bianchiAudizione FIRE al senato sui certificati bianchi
Audizione FIRE al senato sui certificati bianchi
 
img003
img003img003
img003
 

Similar to Session 319

PCI Compliance: How to Remain Compliant and Gain Near Real-Time Analytics on ...
PCI Compliance: How to Remain Compliant and Gain Near Real-Time Analytics on ...PCI Compliance: How to Remain Compliant and Gain Near Real-Time Analytics on ...
PCI Compliance: How to Remain Compliant and Gain Near Real-Time Analytics on ...
Emtec Inc.
 
Why the Cloud can be Compliant and Secure
Why the Cloud can be Compliant and SecureWhy the Cloud can be Compliant and Secure
Why the Cloud can be Compliant and Secure
InnoTech
 
Cloud Security Assessment Methods.pptx
Cloud Security Assessment Methods.pptxCloud Security Assessment Methods.pptx
Cloud Security Assessment Methods.pptx
AdityaChawan4
 
Transforming cloud security into an advantage
Transforming cloud security into an advantageTransforming cloud security into an advantage
Transforming cloud security into an advantage
Moshe Ferber
 
419766865-LAb-QUalys.pdf
419766865-LAb-QUalys.pdf419766865-LAb-QUalys.pdf
419766865-LAb-QUalys.pdf
HarkeemShaw1
 
Wipro's Compliance as a Service [CAAS]
Wipro's Compliance as a Service [CAAS]Wipro's Compliance as a Service [CAAS]
Wipro's Compliance as a Service [CAAS]
Symantec
 
Sustainable Compliance For PCI DSS Standard
Sustainable Compliance For PCI DSS StandardSustainable Compliance For PCI DSS Standard
Sustainable Compliance For PCI DSS Standard
Christian Frahm
 
Taking Lab Management to the Next Level - QualiSystems & Testwise in a joint PPT
Taking Lab Management to the Next Level - QualiSystems & Testwise in a joint PPTTaking Lab Management to the Next Level - QualiSystems & Testwise in a joint PPT
Taking Lab Management to the Next Level - QualiSystems & Testwise in a joint PPT
qualisystems
 
Luncheon 2015-01-15 - Managing Security Requirements in Software Projects by ...
Luncheon 2015-01-15 - Managing Security Requirements in Software Projects by ...Luncheon 2015-01-15 - Managing Security Requirements in Software Projects by ...
Luncheon 2015-01-15 - Managing Security Requirements in Software Projects by ...
North Texas Chapter of the ISSA
 
[EMC] Source Code Protection
[EMC] Source Code Protection[EMC] Source Code Protection
[EMC] Source Code ProtectionPerforce
 
Security Challenges in Cloud Integration - Cloud Security Alliance, Austin Ch...
Security Challenges in Cloud Integration - Cloud Security Alliance, Austin Ch...Security Challenges in Cloud Integration - Cloud Security Alliance, Austin Ch...
Security Challenges in Cloud Integration - Cloud Security Alliance, Austin Ch...
Glen Roberts, CISSP
 
Automated Security & Continuous Compliance on Microsoft Azure
Automated Security & Continuous Compliance on Microsoft AzureAutomated Security & Continuous Compliance on Microsoft Azure
Automated Security & Continuous Compliance on Microsoft Azure
2nd Watch
 
Rightscale Webinar: PCI in Public Cloud
Rightscale Webinar: PCI in Public CloudRightscale Webinar: PCI in Public Cloud
Rightscale Webinar: PCI in Public Cloud
RightScale
 
Con9573 managing the oim platform with oracle enterprise manager
Con9573 managing the oim platform with oracle enterprise manager Con9573 managing the oim platform with oracle enterprise manager
Con9573 managing the oim platform with oracle enterprise manager
OracleIDM
 
Why the Cloud can be Compliant and Secure
Why the Cloud can be Compliant and SecureWhy the Cloud can be Compliant and Secure
Why the Cloud can be Compliant and Secure
InnoTech
 
Behaviour Driven Development: Oltre i limiti del possibile
Behaviour Driven Development: Oltre i limiti del possibileBehaviour Driven Development: Oltre i limiti del possibile
Behaviour Driven Development: Oltre i limiti del possibile
Iosif Itkin
 
45 Minutes to PCI Compliance in the Cloud
45 Minutes to PCI Compliance in the Cloud45 Minutes to PCI Compliance in the Cloud
45 Minutes to PCI Compliance in the Cloud
CloudPassage
 

Similar to Session 319 (20)

PCI Compliance: How to Remain Compliant and Gain Near Real-Time Analytics on ...
PCI Compliance: How to Remain Compliant and Gain Near Real-Time Analytics on ...PCI Compliance: How to Remain Compliant and Gain Near Real-Time Analytics on ...
PCI Compliance: How to Remain Compliant and Gain Near Real-Time Analytics on ...
 
Why the Cloud can be Compliant and Secure
Why the Cloud can be Compliant and SecureWhy the Cloud can be Compliant and Secure
Why the Cloud can be Compliant and Secure
 
Cloud Security Assessment Methods.pptx
Cloud Security Assessment Methods.pptxCloud Security Assessment Methods.pptx
Cloud Security Assessment Methods.pptx
 
Transforming cloud security into an advantage
Transforming cloud security into an advantageTransforming cloud security into an advantage
Transforming cloud security into an advantage
 
419766865-LAb-QUalys.pdf
419766865-LAb-QUalys.pdf419766865-LAb-QUalys.pdf
419766865-LAb-QUalys.pdf
 
CISQ Introduction & Objectives - Dr. Bill Curtis
CISQ Introduction & Objectives - Dr. Bill CurtisCISQ Introduction & Objectives - Dr. Bill Curtis
CISQ Introduction & Objectives - Dr. Bill Curtis
 
Wipro's Compliance as a Service [CAAS]
Wipro's Compliance as a Service [CAAS]Wipro's Compliance as a Service [CAAS]
Wipro's Compliance as a Service [CAAS]
 
Sustainable Compliance For PCI DSS Standard
Sustainable Compliance For PCI DSS StandardSustainable Compliance For PCI DSS Standard
Sustainable Compliance For PCI DSS Standard
 
Taking Lab Management to the Next Level - QualiSystems & Testwise in a joint PPT
Taking Lab Management to the Next Level - QualiSystems & Testwise in a joint PPTTaking Lab Management to the Next Level - QualiSystems & Testwise in a joint PPT
Taking Lab Management to the Next Level - QualiSystems & Testwise in a joint PPT
 
Luncheon 2015-01-15 - Managing Security Requirements in Software Projects by ...
Luncheon 2015-01-15 - Managing Security Requirements in Software Projects by ...Luncheon 2015-01-15 - Managing Security Requirements in Software Projects by ...
Luncheon 2015-01-15 - Managing Security Requirements in Software Projects by ...
 
[EMC] Source Code Protection
[EMC] Source Code Protection[EMC] Source Code Protection
[EMC] Source Code Protection
 
Security Challenges in Cloud Integration - Cloud Security Alliance, Austin Ch...
Security Challenges in Cloud Integration - Cloud Security Alliance, Austin Ch...Security Challenges in Cloud Integration - Cloud Security Alliance, Austin Ch...
Security Challenges in Cloud Integration - Cloud Security Alliance, Austin Ch...
 
AT2012_Pune_UserStories_BhawanaGupta
AT2012_Pune_UserStories_BhawanaGuptaAT2012_Pune_UserStories_BhawanaGupta
AT2012_Pune_UserStories_BhawanaGupta
 
Automated Security & Continuous Compliance on Microsoft Azure
Automated Security & Continuous Compliance on Microsoft AzureAutomated Security & Continuous Compliance on Microsoft Azure
Automated Security & Continuous Compliance on Microsoft Azure
 
Rightscale Webinar: PCI in Public Cloud
Rightscale Webinar: PCI in Public CloudRightscale Webinar: PCI in Public Cloud
Rightscale Webinar: PCI in Public Cloud
 
Master Epm
Master EpmMaster Epm
Master Epm
 
Con9573 managing the oim platform with oracle enterprise manager
Con9573 managing the oim platform with oracle enterprise manager Con9573 managing the oim platform with oracle enterprise manager
Con9573 managing the oim platform with oracle enterprise manager
 
Why the Cloud can be Compliant and Secure
Why the Cloud can be Compliant and SecureWhy the Cloud can be Compliant and Secure
Why the Cloud can be Compliant and Secure
 
Behaviour Driven Development: Oltre i limiti del possibile
Behaviour Driven Development: Oltre i limiti del possibileBehaviour Driven Development: Oltre i limiti del possibile
Behaviour Driven Development: Oltre i limiti del possibile
 
45 Minutes to PCI Compliance in the Cloud
45 Minutes to PCI Compliance in the Cloud45 Minutes to PCI Compliance in the Cloud
45 Minutes to PCI Compliance in the Cloud
 

More from Bobby Curtis

RheoData_23ai_Vector-Datatype-Webinar-2024.pptx
RheoData_23ai_Vector-Datatype-Webinar-2024.pptxRheoData_23ai_Vector-Datatype-Webinar-2024.pptx
RheoData_23ai_Vector-Datatype-Webinar-2024.pptx
Bobby Curtis
 
MySQLHeatwave-TheBasics.pptx
MySQLHeatwave-TheBasics.pptxMySQLHeatwave-TheBasics.pptx
MySQLHeatwave-TheBasics.pptx
Bobby Curtis
 
Oracle GoldenGate 21c New Features and Best Practices
Oracle GoldenGate 21c New Features and Best PracticesOracle GoldenGate 21c New Features and Best Practices
Oracle GoldenGate 21c New Features and Best Practices
Bobby Curtis
 
Terraform & Oracle Cloud Infrastructure
Terraform & Oracle Cloud InfrastructureTerraform & Oracle Cloud Infrastructure
Terraform & Oracle Cloud Infrastructure
Bobby Curtis
 
Oracle GoldenGate on Docker
Oracle GoldenGate on DockerOracle GoldenGate on Docker
Oracle GoldenGate on Docker
Bobby Curtis
 
Oracle GoldenGate Studio Intro
Oracle GoldenGate Studio IntroOracle GoldenGate Studio Intro
Oracle GoldenGate Studio Intro
Bobby Curtis
 
5 Keys to Oracle GoldenGate Implemenations
5 Keys to Oracle GoldenGate Implemenations5 Keys to Oracle GoldenGate Implemenations
5 Keys to Oracle GoldenGate Implemenations
Bobby Curtis
 
Extreme replication at IOUG Collaborate 15
Extreme replication at IOUG Collaborate 15Extreme replication at IOUG Collaborate 15
Extreme replication at IOUG Collaborate 15
Bobby Curtis
 
Examining Oracle GoldenGate Trail Files
Examining Oracle GoldenGate Trail FilesExamining Oracle GoldenGate Trail Files
Examining Oracle GoldenGate Trail Files
Bobby Curtis
 
Exachk and oem12c - IOUG C15LV
Exachk and oem12c - IOUG C15LVExachk and oem12c - IOUG C15LV
Exachk and oem12c - IOUG C15LV
Bobby Curtis
 
Extreme Replication - RMOUG Presentation
Extreme Replication - RMOUG PresentationExtreme Replication - RMOUG Presentation
Extreme Replication - RMOUG Presentation
Bobby Curtis
 
Oracle virtualbox basic to rac attack
Oracle virtualbox basic to rac attackOracle virtualbox basic to rac attack
Oracle virtualbox basic to rac attack
Bobby Curtis
 
How many ways to monitor oracle golden gate - OOW14
How many ways to monitor oracle golden gate - OOW14How many ways to monitor oracle golden gate - OOW14
How many ways to monitor oracle golden gate - OOW14
Bobby Curtis
 
Exachk and oem12c
Exachk and oem12cExachk and oem12c
Exachk and oem12c
Bobby Curtis
 
Oracle GoldenGate Presentation from OTN Virtual Technology Summit - 7/9/14 (PDF)
Oracle GoldenGate Presentation from OTN Virtual Technology Summit - 7/9/14 (PDF)Oracle GoldenGate Presentation from OTN Virtual Technology Summit - 7/9/14 (PDF)
Oracle GoldenGate Presentation from OTN Virtual Technology Summit - 7/9/14 (PDF)
Bobby Curtis
 
GoldenGate Monitoring - GOUSER - 4/2014
GoldenGate Monitoring - GOUSER - 4/2014GoldenGate Monitoring - GOUSER - 4/2014
GoldenGate Monitoring - GOUSER - 4/2014
Bobby Curtis
 
How many ways to monitor oracle golden gate-Collaborate 14
How many ways to monitor oracle golden gate-Collaborate 14How many ways to monitor oracle golden gate-Collaborate 14
How many ways to monitor oracle golden gate-Collaborate 14
Bobby Curtis
 

More from Bobby Curtis (17)

RheoData_23ai_Vector-Datatype-Webinar-2024.pptx
RheoData_23ai_Vector-Datatype-Webinar-2024.pptxRheoData_23ai_Vector-Datatype-Webinar-2024.pptx
RheoData_23ai_Vector-Datatype-Webinar-2024.pptx
 
MySQLHeatwave-TheBasics.pptx
MySQLHeatwave-TheBasics.pptxMySQLHeatwave-TheBasics.pptx
MySQLHeatwave-TheBasics.pptx
 
Oracle GoldenGate 21c New Features and Best Practices
Oracle GoldenGate 21c New Features and Best PracticesOracle GoldenGate 21c New Features and Best Practices
Oracle GoldenGate 21c New Features and Best Practices
 
Terraform & Oracle Cloud Infrastructure
Terraform & Oracle Cloud InfrastructureTerraform & Oracle Cloud Infrastructure
Terraform & Oracle Cloud Infrastructure
 
Oracle GoldenGate on Docker
Oracle GoldenGate on DockerOracle GoldenGate on Docker
Oracle GoldenGate on Docker
 
Oracle GoldenGate Studio Intro
Oracle GoldenGate Studio IntroOracle GoldenGate Studio Intro
Oracle GoldenGate Studio Intro
 
5 Keys to Oracle GoldenGate Implemenations
5 Keys to Oracle GoldenGate Implemenations5 Keys to Oracle GoldenGate Implemenations
5 Keys to Oracle GoldenGate Implemenations
 
Extreme replication at IOUG Collaborate 15
Extreme replication at IOUG Collaborate 15Extreme replication at IOUG Collaborate 15
Extreme replication at IOUG Collaborate 15
 
Examining Oracle GoldenGate Trail Files
Examining Oracle GoldenGate Trail FilesExamining Oracle GoldenGate Trail Files
Examining Oracle GoldenGate Trail Files
 
Exachk and oem12c - IOUG C15LV
Exachk and oem12c - IOUG C15LVExachk and oem12c - IOUG C15LV
Exachk and oem12c - IOUG C15LV
 
Extreme Replication - RMOUG Presentation
Extreme Replication - RMOUG PresentationExtreme Replication - RMOUG Presentation
Extreme Replication - RMOUG Presentation
 
Oracle virtualbox basic to rac attack
Oracle virtualbox basic to rac attackOracle virtualbox basic to rac attack
Oracle virtualbox basic to rac attack
 
How many ways to monitor oracle golden gate - OOW14
How many ways to monitor oracle golden gate - OOW14How many ways to monitor oracle golden gate - OOW14
How many ways to monitor oracle golden gate - OOW14
 
Exachk and oem12c
Exachk and oem12cExachk and oem12c
Exachk and oem12c
 
Oracle GoldenGate Presentation from OTN Virtual Technology Summit - 7/9/14 (PDF)
Oracle GoldenGate Presentation from OTN Virtual Technology Summit - 7/9/14 (PDF)Oracle GoldenGate Presentation from OTN Virtual Technology Summit - 7/9/14 (PDF)
Oracle GoldenGate Presentation from OTN Virtual Technology Summit - 7/9/14 (PDF)
 
GoldenGate Monitoring - GOUSER - 4/2014
GoldenGate Monitoring - GOUSER - 4/2014GoldenGate Monitoring - GOUSER - 4/2014
GoldenGate Monitoring - GOUSER - 4/2014
 
How many ways to monitor oracle golden gate-Collaborate 14
How many ways to monitor oracle golden gate-Collaborate 14How many ways to monitor oracle golden gate-Collaborate 14
How many ways to monitor oracle golden gate-Collaborate 14
 

Recently uploaded

Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdfSmart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
91mobiles
 
JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
RTTS
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
DianaGray10
 
Elevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object CalisthenicsElevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object Calisthenics
Dorra BARTAGUIZ
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
Kari Kakkonen
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Jeffrey Haguewood
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
DanBrown980551
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
BookNet Canada
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
James Anderson
 
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
Product School
 
When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...
Elena Simperl
 
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMsTo Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
Paul Groth
 
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Ramesh Iyer
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
Product School
 
Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !
KatiaHIMEUR1
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance
 

Recently uploaded (20)

Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdfSmart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
 
JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
 
Elevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object CalisthenicsElevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object Calisthenics
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
 
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
 
When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...
 
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMsTo Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
 
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
 
Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
 

Session 319

  • 1. Session 319: Security Compliance using Oracle Enterprise Manager 12c Bobby Curtis, MBA Solution Architect BIAS Corporation April 2013
  • 2. •  Founded in 2000 •  Oracle Platinum Partner with 20+ specializations •  Distinguished Oracle Leader –  Technology Momentum –  Portal Blazer Award –  Titan Award – Red Stack + HW Momentum –  Excellence in Innovation •  Management Team is Ex-Oracle •  Location(s): Atlanta, Washington D.C., Offshore – Hyderabad and Chennai, India About BIAS •  Inc.500 fastest growing private company in the U.S. for the 3rd Time •  Voted Best Place to work in Atlanta for 2nd year
  • 3. Bobby Curtis, MBA •  Douglasville, Georgia (west side of Atlanta) •  Solution Architect, BIAS Corp. About Presenter •  Implementation Specialist for Core Technologies •  IOUG, ODTUG, & GOUSER •  Using Oracle products since 2001 •  Previous Life: Military/Systems Administrator Blog: http://www.dbasolved.com Twitter: @curtisbl294 Email: bobby.curtis@biascorp.com curtisbl@gmail.com
  • 4. §  Compliance   §  Customer  Story  -­‐  CCH   §  Puzzle  Pieces   Session Agenda §  Configura8on   §  Addi8onal  Informa8on   §  Customer  Improvements   §  Wrap-­‐Up  
  • 6. Compliance Management What  is  compliance  management?   The  ability  to  evaluate  the   compliance  of  targets  and   systems  as  they  are  related  to   best  prac8ces  for  configura8on,   security,  and  storage.  
  • 7. Compliance Overview Compliance  solu8on  consists  of:  
  • 8. What  do  these  numbers     have  to  do  with  security  compliance?   Compliance Overview 6                Frameworks   :0   50            Standards   :23   :115        Rules   1827  
  • 10. Who  is…   •  Leading  provider  of  Tax,  Accoun8ng  and  Audit   Informa8on  SoUware  for  professionals   •  Subsidiary  of  Wolters  Kluwer  Tax  &  Accoun8ng   Customer Story •  Based  in  Riverwoods,  Ill.,  office  in  Kennesaw,  GA.   •  Largest  customer  is  Internal  Revenue  Service  (IRS)   •  Booth  1318    
  • 11. •  Reliable  monitoring  for  3  RAC  environments   •  High  security  requirements   Customer Story •  Needed  to  enforce  compliance   •  Annual  audits  are  8me  consuming  
  • 13. There  are  three  pieces  to  the  compliance   Puzzle Pieces, oh my… puzzle.    They  are  the  building  blocks  for   compliance  and  are  hierarchical  structure.   1.  Frameworks   2.  Standards   3.  Rules   ü  Real-­‐Time  Facets*   ü  Templates*  
  • 14. Puzzle Pieces : Framework A  compliance  framework  is  a  hierarchical  structure   where  any  node  can  be  mapped  to  one  or  more   compliance  standards  and  compliance  standard   rules.   2  Types  of  Frameworks:     §  Oracle  Provided   §  Payment  Card  Industry  (PCI)   §  Generic   §  User-­‐Defined   §  Defined  to  sa8sfy  the  needs  of  your  organiza8on  
  • 15. Puzzle Pieces : Standards A  compliance  standard  is  a  collec8on  of  checks  or   rules.   Standards-­‐Hierarchical  Structure:     §  Compliance  Rules   §  Rule  Folders   §  Hierarchical  structure  the  constrains  compliance  rules   §  Compliance  Standards   §  Can  include  other  compliance  standards  
  • 16. What  do  standards  do:   Puzzle Pieces : Standards   §  Represent  Industry-­‐wide  standards,  per  target   §  Used  as  reference  configura8on/cer8fied  configura8on   §  Describe  best  prac8ces  for  enterprise   Security  Compliance  Standards  By   Target  Type   Automa8c  Storage  Management  (ASM)   2   Cluster   1   Cluster  Database   7   Database  Instance   9   Host   2   Listener   2   Total   23  
  • 17. A  compliance  rule  is  a  test  that  determines  if   configura8on  data  change  affects  compliance.     Based  on  the  result,  the  compliance  score  is   Puzzle Pieces : Rules calculated.   3  Types  of  Rules:   §  Repository  Rules   §  Check  against  metrics  in  management  repository   §  Weblogic  Server  Signature  Rules   §  Describe  poten8al  problems  based  on  info  about  Weblogic   Server  and  environment   §  Real-­‐Time  Monitoring   §  Monitors  ac8ons  performed  by  users  on  targets  
  • 18. Puzzle Pieces : Templates Enable  security  compliance;  templates  have  to  be   enabled.  
  • 19. Evaluation…Understand Number  of  targets   evaluated  as  Cri8cal,   Warning,  or  Compliant   Average  Score  for  Evalua8on   Number  of  Cri8cal,   Compliance  Score  Ra9ngs   Warning,  or  Minor  Warning   Cri9cal   <  60   viola8ons  across  all  targets   Warning   <  80   Compliant   >  80    
  • 20. Compliance  Summary  &  Details     §  Enterprise  Summary   Evaluation… Review §  Compliance  Dashboard  
  • 22. Configure: Library 3   2   1   N/A  
  • 26. Compliance  Standards  are:     §  Hierarchical  in  nature   §  Must  have  at  least  1  rule   Configure: Standards   Adding  Rules/Standards  is   simple!     Right  click-­‐>Edit-­‐>Add  
  • 27. Configure: Framework §  Top  most  level  of  compliance   §  Only  standards  can  be  added   §  Standards  in  subgroups  
  • 28. §  Oracle  Security  Template   §  Immediately  available   (some  delay)   Results
  • 30. Dashboard  Consists  of:     §  Compliance  Framework   Summary   §  Compliance  Summary   §  Least  Compliant  Generic   Systems   Results §  Most  Recently  Discovered   Unmanaged  Hosts   §  Least  Compliant  Targets  
  • 32. Compliance  from  the  command  line:   §  export_compliance_group   §  export_compliance_standard_rule     §  export_standard               §  import_compliance_object       EMCLI Options
  • 33. Views  for  Compliance  (SYSMAN)   §  MGMT$COMPLIANCE_STANDARD_GROUP   §  MGMT$COMPLIANCE_STANDARD   §  MGMT$COMPLIANCE_STANDARD_RULE   §  MGMT$COMPLIANCE_SUMMARY   SQL Options §  MGMT$COMPLIANT_TARGETS   §  MGMT$COMPLIANCE_TREND   §  MGMT$COMPOSITE_CS_EVAL_SUMMARY   Oracle  Enterprise  Manager  Cloud  Control  Extensibility  Programmers  Guide   Chapter  18      
  • 34. To  use  compliance  standards:   §  CREATE_COMPLIANCE_ENTITY   Privileges & Roles §  FULL_ANY_COMPLIANCE_ENTITY   §  VIEW_ANY_COMPLIANCE_FWK   §  MANAGE_TARGET_COMPLIANCE   §  VIEW   §  EM_COMPLIANCE_DESIGNER  (ROLE)   §  EM_COMPLIANCE_OFFICE  (ROLE)  
  • 36. §  Able  to  monitor  in  all  environments   §  Has  a  easier  and  measurable  way  of  enforcing   compliance  across  environments   Customer Story   §  Expected  to  reduce  annual  audit  8mes  by   40%-­‐50%  
  • 37. §  Brief  customer  story   §  Talked  about  compliance  and  its  importance   §  Implemented  security  aspects  of  the  compliance   model  and  how  to  review  results   §  Discussed  addi8onal  op8ons  for  compliance   Wrap Up §  Results  of  customer  implemen8ng  compliance  
  • 39. Thank You for Attending Blog: http://www.dbasolved.com Twitter: @curtisbl294 Email: bobby.curtis@biascorp.com curtisbl@gmail.com hrp://www.biascorp.com