Re: Securing data from Database Admin



Oracle 11g has added a suite of security functions. Ask your DBA to help you. S/he should not have any issue with helping you secure your data to whatever level you want or need to, including restricting their own access. For instance, you can still patch the database without being able to look at the data and you can still back up and restore data even if it's encrypted.

http://www.oracle.com/database/database-vault.html
http://www.oracle.com/database/advanced-security.html
http://www.oracle.com/technology/deploy/security/database-security/secure-application-roles/index.html
http://www.oracle.com/technology/deploy/security/database-security/virtual-private-database/index.html
http://www.oracle.com/technology/deploy/security/database-security/transparent-data-encryption/index.html

I haven't implemented these in 11g myself and don't have any plans to.

-Mike

WALI wrote:
Is there a way we can secure data within (Oracle 9i) database? Supposingly there is an application developed by internal developers and it's backend database is administered by a DB Admin. There is no segregation of duties between development and live environments due to resource constraints.

Is there a way data can be protected from being revealed to or being tempered by DB Admin? He would only be called in when there's some kind of malfunction that too under the watchful eyes of project team leader.

Any thoughts to bring in preventive/detective controls over DB Admin activities?






Relevant Pages

  • Securing data from Database Admin
    ... Is there a way we can secure data within database? ... Supposingly there is an application developed by internal developers and it's backend database is administered by a DB Admin. ...
    (Security-Basics)
  • Re: Running developers as standard users in Vista with UAC enabled
    ... kind of rubbish programs we see that won't run properly without admin rights. ... Plenty of rubbish but none that require admin. ... All .NET based line-of-business application developers should run as standard user, otherwise they'll end up writing the usual ...
    (microsoft.public.vsnet.general)
  • Re: Running developers as standard users in Vista with UAC enabled
    ... I have been given the task of researching Vista and UAC and the feasibility ... Developers are going to have a hard ... if not impossible time without admin rights. ... Studio to run 'as admin' so that it runs under admin rights. ...
    (microsoft.public.vsnet.general)
  • Re: Administrator Priviledges on local system.
    ... So don't give them the password for the admin account. ... developers doing stupid things that you then have to go in and fix. ... They want admin rights, ...
    (microsoft.public.security)
  • Re: Administrator Priviledges on local system.
    ... So don't give them the password for the admin account. ... developers doing stupid things that you then have to go in and fix. ... They want admin rights, ...
    (microsoft.public.win2000.security)