Detective Controls 1 - DAM & Auditing
%41
SafeAssign Originality Report Database Security - 201950 - CRN167 - Mercer • Week 8 Paper
%41Total Score: High riskSanthosh Muthyapu Submission UUID: e076bcd8-c5c6-d7d9-9dd9-bb025743fc41
Total Number of Reports
1 Highest Match
41 % Database week8.docx
Average Match
41 % Submitted on
08/21/19 12:08 PM EDT
Average Word Count
667 Highest: Database week8.docx
%41Attachment 1
Institutional database (10)
Student paper Student paper Student paper
Student paper Student paper Student paper
Student paper Student paper Student paper
Student paper
Top sources (3)
Excluded sources (0)
View Originality Report - Old Design
Word Count: 667 Database week8.docx
6 8 1
10 4 2
9 5 3
7
6 Student paper 8 Student paper 1 Student paper
Source Matches (14)
Student paper 75%
Student paper 72%
Student paper 64%
Student paper 63%
Running Head: DAM & AUDITING 1
DAM & AUDITING 2
Topic: Detective Controls 1 - DAM & Auditing Name: Santhosh Muthyapu Course: Database Security Date of Submission: 08/21/2019
DAM & AUDITING
Information technology has changed the way organizations used to work in various ways. The programs of continuous controls monitoring and continuous auditing are beneficial to every corporation. “Audits are the examination as well as evaluation of the organization's infrastructure policies and operations “(Groomer, & Murthy, 2018). This enables businesses to be able to adhere to the intended levels of performance and effectiveness. This is simply because all he configured database actions are monitored and recorded. For one to be able to perform auditing there must be appropriate system privileges that are granted. Oracle 12c has established
two innovative roles, the AUDIT_ADMIN, and the AUDIT _VIEWER. The major reason for doing this is to simply facilitate better separation of duties for the auditors. “These two new roles support Unified Auditing which is managed by creating and enabling audit policies” (Spyker, 2017). The use of unified auditing was
introduced to mitigate the problem that existed initially where it was hard managing auditing. This has therefore made it easier managing auditing as well as auditing related data. The use of Unified Auditing keeps track of all audit data in a single audit trail. “So that a person is allowed to perform any kind of auditing, one must
be granted either the role of AUDIT _ADMIN or the AUDIT_VIEWER” (Daghighi, 2019). The role of AUDIT_VIEWER is given to the auditors performing external audits. This allows the auditors to view the display of audit transactions that are processed by the PIX/PDQ manager based on the audit trail. The given information helps one to be able to monitor transactions and see if there is any inappropriate activity. This gives a graphical interface to view audit information. It, therefore, becomes easier for one to be able to filter the list of transactions that are displayed on the audit page. One can now narrow down the transaction by using source ID, event ID, date range among other sources. On the other hand, AUDIT_ADMIN helps administrators to create, alter and enable audit policies. The auditors can also be able to
see and analyze audit data. With this role, therefore, it becomes easier for one to configure auditing as well as administering both unified and fine-grained audit
policies. Typically, this role is given out to the security administrators. Having these two roles, it means that one drops the earlier release before upgrading to
these two new roles. It becomes as easier to log into the database as a user who has been granted the role of AUDIT_ADMIN. With these two new roles, it has become easier to enhance audit performance. This has increased the efficiency and effectiveness as compared to the previous releases that oracle database had done. This is simply because controlling the way the audit report is printed on the audit trail has become easier. The audit data can immediately be written or it is also
possible to queue it in the memory. This has made it more flexible and less complicated with these new roles being put in place. This has helped simplify the
configuration of database auditing in Oracle 12c.
References
Daghighi, A. (2019). Application of an Artificial Neural Network as a Third-Party Database Auditing System. Groomer, S. M., & Murthy, U. S. (2018).
Continuous auditing of database applications: An embedded audit module approach. In Continuous Auditing: Theory and Application (pp. 105-124). Emerald
Publishing Limited. https://docs.oracle.com/en/database/oracle/oracle-database/12.2/upgrd/unified-auditing-audit_admin-audit_viewer-changes.html#GUID-
0867243D-4F4B-49B4-A7A5-C5EA98F59172
http://www.dba86.com/docs/oracle/12.2/DBSEG/introduction-to-auditing.htm
https://docs.oracle.com/database/121/TDPSG/GUID-BF747771-01D1-4BFB-8489-08988E1181F6.htm#TDPSG50051
Spyker, J. D. (2017). U.S. Patent No. 9,613,082. Washington, DC: U.S. Patent and Trademark Office.
1
2
3
2
4
5
6
7
6 6
6
8
9
10
1
Student paper
For one to be able to perform auditing there must be appropriate system privileges that are granted. Oracle 12c has established two innovative roles, the AUDIT_ADMIN, and the AUDIT _VIEWER.
Original source
To perform the auditing, user must be granted with the appropriate system privileges AUDIT ROLES in Oracle 12c - AUDIT_ADMIN and AUDIT_VIEWER
2
Student paper
“These two new roles support Unified Auditing which is managed by creating and enabling audit policies” (Spyker, 2017).
Original source
Unified Auditing is managed by creating and enabling audit policies
3
Student paper
The use of Unified Auditing keeps track of all audit data in a single audit trail.
Original source
All audit data is found in UNIFIED_AUDIT_TRAIL view
2
Student paper
On the other hand, AUDIT_ADMIN helps administrators to create, alter and enable audit policies.
Original source
AUDIT_ADMIN has privilege create, drop and alter audit policies
Student paper 64%
Student paper 63%
Student paper 75%
Student paper 63%
Student paper 100%
Student paper 100%
Student paper 100%
Student paper 100%
Student paper 100%
Student paper 100%
4
Student paper
With this role, therefore, it becomes easier for one to configure auditing as well as administering both unified and fine-grained audit policies.
Original source
The user with this role would be able to configure the auditing and also administer both the fine-grained audit policies and the unified audit policies
5
Student paper
Typically, this role is given out to the security administrators.
Original source
ADMIT_ADMIN role is granted typically to security administrators
6
Student paper
The audit data can immediately be written or it is also possible to queue it in the memory.
Original source
The audit data can be written immediately or it can also be queued in the memory
7
Student paper
This has helped simplify the configuration of database auditing in Oracle 12c.
Original source
Unified Auditing in Oracle Database 12c
6
Student paper
M., & Murthy, U.
Original source
M., & Murthy, U
6
Student paper
Continuous auditing of database applications: An embedded audit module approach. In Continuous Auditing: Theory and Application (pp.
Original source
Continuous auditing of database applications An embedded audit module approach In Continuous Auditing Theory and Application (pp
6
Student paper
Emerald Publishing Limited.
Original source
Emerald Publishing Limited
8
Student paper
https://docs.oracle.com/en/database/ora cle/oracle-database/12.2/upgrd/unified- auditing-audit_admin-audit_viewer- changes.html#GUID-0867243D-4F4B- 49B4-A7A5-C5EA98F59172
Original source
https://docs.oracle.com/en/database/ora cle/oracle-database/12.2/upgrd/unified- auditing-audit_admin-audit_viewer- changes.html#GUID-0867243D-4F4B- 49B4-A7A5-C5EA98F59172 “
9
Student paper
http://www.dba86.com/docs/oracle/12.2/ DBSEG/introduction-to-auditing.htm
Original source
http://www.dba86.com/docs/oracle/12.2/ DBSEG/introduction-to-auditing.htm
10
Student paper
https://docs.oracle.com/database/121/T DPSG/GUID-BF747771-01D1-4BFB-8489- 08988E1181F6.htm#TDPSG50051
Original source
https://docs.oracle.com/database/121/T DPSG/GUID-BF747771-01D1-4BFB-8489- 08988E1181F6.htm#TDPSG50051