Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Management
[Top] [All Lists]

RE: Oracle Standard Operating Environment

Subject: RE: Oracle Standard Operating Environment
Date: Mon, 23 Jan 2006 15:24:37 -0600
It sounds like what you're looking for is what is often referred to as a
"secure configuration guide" (or something similar).  Many organizations
develop these for the operating system  and network levels, and
depending on the maturity of their security program, they may also
include the database and application level, too.  Vendors may also put
out such guidelines, but they often only tell you the various
security-related options and you still need to do your own risk
assessment to determine what settings are appropriate for your
environment.

One source you might want to consider is the Center for Internet
Security (CIS) at http://www.cisecurity.com (note: this is not an
"endorsement" from me or my agency - I'm just pointing out a possible
source).  They've put out a security "benchmark" for a couple of
versions of Oracle, as well as the corresponding "scoring tool" to tell
you how your system compares to their benchmark.  It should be a good
starting point to beef up security in the Oracle environment.

Hope that is helpful.

Steve Riffel 
CPP, CISM, CISSP, CHSP, NSA IAM, VA CSO, ATO 
Chief, Security Services 
VA Austin Automation Center (AAC) 


-----Original Message-----
From: a55mnky@yahoo.com [mailto:a55mnky@yahoo.com] 
Sent: Friday, January 20, 2006 11:30 AM
To: security-management@securityfocus.com
Subject: Oracle Standard Operating Environment

Please bear with me - I am not really sure where to post this.

I am the security director for my company.  I have been asked to develop
a standard operating environment document for our DBA team.  Currently
they are doing everything differently depending upon which DBA builds
the server.

My expertise in Oracle is limited at best.  I have searched and searched
and either I am using the wrong phrase (standard operating environment,
SOE) or nothing exists on line.  Can anybody provide some pointers or if
possible a sanitized SOE document from your organization.

Bear in mind this is not an audit or assessment - what I need is a
template that says - do this, then do this, then do that, etc.

Thanks in advance

<Prev in Thread] Current Thread [Next in Thread>