Preview

Oracle EBS

Powerful Essays
Open Document
Open Document
2271 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
Oracle EBS
Oracle E-Business Suite

APPS, SYSADMIN, and oracle
Securing Generic Privileged Accounts

May 15, 2014
Mike Miller

Stephen Kost

Chief Security Officer

Chief Technology Officer

Integrigy Corporation

Integrigy Corporation

Phil Reimann
Director of Business Development
Integrigy Corporation

Agenda

Best Practices

Overview

1

2
EBS Privileged
Accounts

3

Q&A

4
Logging
Auditing &
Monitoring

5

About Integrigy
ERP Applications

Databases

Oracle E-Business Suite

Oracle, SQL Server, MySQL

Products

AppSentry

Services
Validates
Security

ERP Application and Database
Security Auditing Tool

AppDefend

Verify
Security

Ensure
Compliance

Security Assessments
Oracle EBS, OBIEE, Databases,
Sensitive Data, Penetration Testing

Compliance Assistance
SOX, PCI, HIPAA

Protects
Oracle EBS

Enterprise Application Firewall for the Oracle E-Business Suite

Build
Security

Security Design Services
Auditing, Encryption, DMZ

You

Agenda

Best Practices

Overview

1

2
EBS Privileged
Accounts

3

Q&A

4
Logging
Auditing &
Monitoring

5

{ generic privileged account } application, database, or operating system account used for administration by multiple people and has significant privileges

Generic Privileged Accounts


Oracle E-Business Suite is defined by generic privileged accounts in each layer of the technology stack
-



Multiple highly privileged accounts
Generic accounts that must be used to manage the application and database

Majority of all data breaches committed by insiders -

Some intentional
Most accidental

Oracle EBS Generic Privileged Accounts
Oracle
E-Business Suite
Oracle
Database
Operating
System
(Unix and Linux)

SYSADMIN seeded application accounts

APPS, APPLSYS
SYS, SYSTEM
Oracle EBS schemas (GL, AP, ...)

root oracle, applmgr

Generic Privileged Account Inter-Dependency

You May Also Find These Documents Helpful

  • Satisfactory Essays

    IT255 Project 1

    • 663 Words
    • 2 Pages

    At Richman Investments the personnel is accountable for the appropriate use of IT assets. Therefore, it is in the best interest of the organization to ensure employees handle security procedures with integrity. It is essential to create a strong AUP (Acceptable Use Policy) procedure and as part of the process, require employees sign an agreement to guarantee they understand and conform to implemented rules and regulations. In addition, the company will conduct security awareness training, annual security exercises, notices about securing information, and constant reminders security is everyone’s responsibility.…

    • 663 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    BSA 375 Week 3 Individual

    • 793 Words
    • 3 Pages

    The level of security and its effectiveness in an application is a concern for all software development projects. Operations and Information Technology will hold key responsibility in implementation and maintenance of the software security measures. These measures will include but not be limited to firewalls, intrusion detection systems, credential verification, and standard backup operations (Valacich, 2012). This responsibility isn’t limited to just these measures or to this scope of responsibility. All hands that take part in development will have some responsibility in assuring appropriate security measures are developed, implemented, and maintained.…

    • 793 Words
    • 3 Pages
    Good Essays
  • Good Essays

    Nt1310 Unit 7 Week 7

    • 594 Words
    • 3 Pages

    This concentration was developed in conjunction with the U.S. National Security Agency (NSA) providing an invaluable tool for any systems security engineering professional. CISSP-ISSEP is the guide for incorporating security into projects, applications, business processes, and all information systems. Security professionals are hungry for workable methodologies and best practices that can be used to integrate security into all facets of business operations(New Horizon,2016)…

    • 594 Words
    • 3 Pages
    Good Essays
  • Good Essays

    module 6 dba

    • 3227 Words
    • 11 Pages

    Provide a detailed description of the historical importance of each of the famous people, key terms and places listed below. Focus on explaining what is most important to know about each including information that helps explain who, what, when, where and why. Use the lessons listed in parentheses to find the necessary information and avoid using Google, Wikipedia or other internet sources.…

    • 3227 Words
    • 11 Pages
    Good Essays
  • Good Essays

    Module 1: EB Tylor

    • 1163 Words
    • 5 Pages

    1. EB Tylor states religion is rooted in spirit worship, and is a common aspect of most religions. This particular aspect of religion strikes a chord with me in that worship is a central element in many religion, as well as thoughts on man’s spirit and the afterlife His notion is not far off when you consider that Jesus said, “God is Spirit and those who worship him must worship him in Spirit and truth”. The fact that God is in control of everything, and that he is worthy of all our worship, his views at least acknowledge the existence of a God.…

    • 1163 Words
    • 5 Pages
    Good Essays
  • Satisfactory Essays

    enterprise systems

    • 319 Words
    • 1 Page

    Measuring Enterprise Impact is very imortant. One of the key focuses of an enterprise is information. Huge amounts of data are made during each of the transactions in the company. Processing un-tampered data into valuable information allows an enterprise to take more error free decision into action. Information technologies give support in big business systems like (ERP) Enterprise Resource Planning, utilized in recognizing, extracting and analyzing business data, such as, sales revenue by product and/or department. Measuring data is strenuous, and companies have to have multiplex systems for tracking ERP. Outsourcing Data.…

    • 319 Words
    • 1 Page
    Satisfactory Essays
  • Best Essays

    six key aspects of EBM

    • 2274 Words
    • 8 Pages

    Ecosystem-based management (EBM) is a great tool to protect not only the environment, but to do it in a way that is not detrimental to humans or the economy. Traditional environmental movements have for the most part been a failure since they advanced the environment at the expense of the economy and of humans. However, we cannot continue in this same manner or else we will live in a world that is too polluted to live in. One of the greatest minds, Stephen Hawking stated, “We are in danger of destroying ourselves by our greed and stupidity. We cannot remain looking inwards at ourselves on a small and increasingly polluted and overcrowded planet”. EBM is an approach that helps protect the environment but also takes into consideration both the economy and social aspects. This paper will provide an analysis of EBM by first giving an explanation of what it is, and then provide examples of adopting EBM, and finally highlight some barriers to EBM.…

    • 2274 Words
    • 8 Pages
    Best Essays
  • Powerful Essays

    In relation to developing a sound plan of action for the student, the special education (SPED) team was created to ensure that the needs were continuously being met. In consideration of legislation such as IDEA and the NCLB, the SPED team is comprised of the…

    • 1514 Words
    • 7 Pages
    Powerful Essays
  • Good Essays

    ESEA DBQ

    • 474 Words
    • 2 Pages

    The Elementary and Secondary Education Act (ESEA) was the first national education law. It’s goal was to provide federal funds for education, and help provide access to education for less fortunate. I believe the ESEA is an example of federal leadership because the government took charge by making choices that would benefit schools.…

    • 474 Words
    • 2 Pages
    Good Essays
  • Powerful Essays

    Ebscohost

    • 1141 Words
    • 5 Pages

    For this activity you will do a library search for resources in your area of professional or research interest. Locate two peer-reviewed journal articles, one book chapter, and one scholarly resource (website or other resource). Then, prepare a brief paper on your library search and your results. First, fill out this chart and for each resource include the following: [pic]…

    • 1141 Words
    • 5 Pages
    Powerful Essays
  • Powerful Essays

    Erp in Tosco B

    • 15289 Words
    • 62 Pages

    Most of the Tosco people assigned to the project were assigned part-time. It was for the advantage of part-time workers who are brilliant in terms of working, so that they can work in the firm anytime.…

    • 15289 Words
    • 62 Pages
    Powerful Essays
  • Good Essays

    Asbs

    • 1057 Words
    • 5 Pages

    Music plays an important role in the socialization of children and adolescents. Popular music is present almost everywhere, and it is easily available through the radio, various recordings, the Internet, and new technologies, allowing adolescents to hear it in diverse settings and situations, alone or shared with friends. It started with an anonymous 14 year old girl in a chat room talking about chart topping songs when her friend revealed the meaning behind a song’s questionable lyrics. Her response? “i love this song, and i don’t really care what the lyrics mean :P”…

    • 1057 Words
    • 5 Pages
    Good Essays
  • Powerful Essays

    With Oracle’s Specialization Program, Oracle Partners can become specialized in a wide range of Oracle’s growing product portfolio. The Specialization Catalog offers a consolidated view of all qualifying specializations launched and planned as part of the Specialization Program. The Specialization Catalog covers:  Specialization Readiness– which provides the status of all qualifying specializations launched and planned o Database o Middleware o Applications o Server and Storage Systems o Engineered Systems o Industries o Cloud Services  Specialization Criteria – which provides detail information on business and competency criteria required to join the program  Non-Qualifying Specializations – which offers a consolidated overview of the timeframe for Specializations becoming Non-Qualifying Only qualifying specializations will count towards the criteria to join Oracle’s Specialization Program and apply towards specializations benefits. To be a “qualifying” version of a specialization, a specialization must be either in the most recent product version or in the “phase-out” status. Product version Specializations are tagged and they last for one-year; during this period of time, you can work towards meeting the criteria for the newer corresponding version of the Specialization. Specializations on previous product versions will remain valid until the product version has reached its End Of Service Life (EOSL). They will not count towards the Specialization Program. Partners can apply for Qualifying Specializations when all accreditations and certification exams are in production. More information is available in the Overview and Frequently Asked Questions for Product Version Specialization document.…

    • 12031 Words
    • 88 Pages
    Powerful Essays
  • Good Essays

    2. The Global Financial Architecture in R12 includes to following new features____? Mark for Review…

    • 21821 Words
    • 159 Pages
    Good Essays
  • Better Essays

    Ebsilon Professional

    • 2286 Words
    • 10 Pages

    By means of the component library of EBSILON®Professional you map the topology of your cycle in a precise…

    • 2286 Words
    • 10 Pages
    Better Essays

Related Topics