Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Oracle Standard Operating Environment |
|---|---|
| Date: | Mon, 23 Jan 2006 15:24:37 -0600 |
It sounds like what you're looking for is what is often referred to as a "secure configuration guide" (or something similar). Many organizations develop these for the operating system and network levels, and depending on the maturity of their security program, they may also include the database and application level, too. Vendors may also put out such guidelines, but they often only tell you the various security-related options and you still need to do your own risk assessment to determine what settings are appropriate for your environment. One source you might want to consider is the Center for Internet Security (CIS) at http://www.cisecurity.com (note: this is not an "endorsement" from me or my agency - I'm just pointing out a possible source). They've put out a security "benchmark" for a couple of versions of Oracle, as well as the corresponding "scoring tool" to tell you how your system compares to their benchmark. It should be a good starting point to beef up security in the Oracle environment. Hope that is helpful. Steve Riffel CPP, CISM, CISSP, CHSP, NSA IAM, VA CSO, ATO Chief, Security Services VA Austin Automation Center (AAC) -----Original Message----- From: a55mnky@yahoo.com [mailto:a55mnky@yahoo.com] Sent: Friday, January 20, 2006 11:30 AM To: security-management@securityfocus.com Subject: Oracle Standard Operating Environment Please bear with me - I am not really sure where to post this. I am the security director for my company. I have been asked to develop a standard operating environment document for our DBA team. Currently they are doing everything differently depending upon which DBA builds the server. My expertise in Oracle is limited at best. I have searched and searched and either I am using the wrong phrase (standard operating environment, SOE) or nothing exists on line. Can anybody provide some pointers or if possible a sanitized SOE document from your organization. Bear in mind this is not an audit or assessment - what I need is a template that says - do this, then do this, then do that, etc. Thanks in advance
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Purchasing Firewalls through MSSP or In-House, onyx3 |
|---|---|
| Next by Date: | Call For Paper - SyScan'06 Singapore, organiser@syscan.org |
| Previous by Thread: | Re: Oracle Standard Operating Environment, Richard Sullivan |
| Next by Thread: | NY Privacy law similar to CA1386, Nay, Eric |
| Indexes: | [Date] [Thread] [Top] [All Lists] |