Detective Controls 1 - DAM & Auditing

profilesanthosh990
week8DS.pdf

%41

SafeAssign Originality Report Database Security - 201950 - CRN167 - Mercer • Week 8 Paper

%41Total Score: High riskSanthosh Muthyapu Submission UUID: e076bcd8-c5c6-d7d9-9dd9-bb025743fc41

Total Number of Reports

1 Highest Match

41 % Database week8.docx

Average Match

41 % Submitted on

08/21/19 12:08 PM EDT

Average Word Count

667 Highest: Database week8.docx

%41Attachment 1

Institutional database (10)

Student paper Student paper Student paper

Student paper Student paper Student paper

Student paper Student paper Student paper

Student paper

Top sources (3)

Excluded sources (0)

View Originality Report - Old Design

Word Count: 667 Database week8.docx

6 8 1

10 4 2

9 5 3

7

6 Student paper 8 Student paper 1 Student paper

Source Matches (14)

Student paper 75%

Student paper 72%

Student paper 64%

Student paper 63%

Running Head: DAM & AUDITING 1

DAM & AUDITING 2

Topic: Detective Controls 1 - DAM & Auditing Name: Santhosh Muthyapu Course: Database Security Date of Submission: 08/21/2019

DAM & AUDITING

Information technology has changed the way organizations used to work in various ways. The programs of continuous controls monitoring and continuous auditing are beneficial to every corporation. “Audits are the examination as well as evaluation of the organization's infrastructure policies and operations “(Groomer, & Murthy, 2018). This enables businesses to be able to adhere to the intended levels of performance and effectiveness. This is simply because all he configured database actions are monitored and recorded. For one to be able to perform auditing there must be appropriate system privileges that are granted. Oracle 12c has established

two innovative roles, the AUDIT_ADMIN, and the AUDIT _VIEWER. The major reason for doing this is to simply facilitate better separation of duties for the auditors. “These two new roles support Unified Auditing which is managed by creating and enabling audit policies” (Spyker, 2017). The use of unified auditing was

introduced to mitigate the problem that existed initially where it was hard managing auditing. This has therefore made it easier managing auditing as well as auditing related data. The use of Unified Auditing keeps track of all audit data in a single audit trail. “So that a person is allowed to perform any kind of auditing, one must

be granted either the role of AUDIT _ADMIN or the AUDIT_VIEWER” (Daghighi, 2019). The role of AUDIT_VIEWER is given to the auditors performing external audits. This allows the auditors to view the display of audit transactions that are processed by the PIX/PDQ manager based on the audit trail. The given information helps one to be able to monitor transactions and see if there is any inappropriate activity. This gives a graphical interface to view audit information. It, therefore, becomes easier for one to be able to filter the list of transactions that are displayed on the audit page. One can now narrow down the transaction by using source ID, event ID, date range among other sources. On the other hand, AUDIT_ADMIN helps administrators to create, alter and enable audit policies. The auditors can also be able to

see and analyze audit data. With this role, therefore, it becomes easier for one to configure auditing as well as administering both unified and fine-grained audit

policies. Typically, this role is given out to the security administrators. Having these two roles, it means that one drops the earlier release before upgrading to

these two new roles. It becomes as easier to log into the database as a user who has been granted the role of AUDIT_ADMIN. With these two new roles, it has become easier to enhance audit performance. This has increased the efficiency and effectiveness as compared to the previous releases that oracle database had done. This is simply because controlling the way the audit report is printed on the audit trail has become easier. The audit data can immediately be written or it is also

possible to queue it in the memory. This has made it more flexible and less complicated with these new roles being put in place. This has helped simplify the

configuration of database auditing in Oracle 12c.

References

Daghighi, A. (2019). Application of an Artificial Neural Network as a Third-Party Database Auditing System. Groomer, S. M., & Murthy, U. S. (2018).

Continuous auditing of database applications: An embedded audit module approach. In Continuous Auditing: Theory and Application (pp. 105-124). Emerald

Publishing Limited. https://docs.oracle.com/en/database/oracle/oracle-database/12.2/upgrd/unified-auditing-audit_admin-audit_viewer-changes.html#GUID-

0867243D-4F4B-49B4-A7A5-C5EA98F59172

http://www.dba86.com/docs/oracle/12.2/DBSEG/introduction-to-auditing.htm

https://docs.oracle.com/database/121/TDPSG/GUID-BF747771-01D1-4BFB-8489-08988E1181F6.htm#TDPSG50051

Spyker, J. D. (2017). U.S. Patent No. 9,613,082. Washington, DC: U.S. Patent and Trademark Office.

1

2

3

2

4

5

6

7

6 6

6

8

9

10

1

Student paper

For one to be able to perform auditing there must be appropriate system privileges that are granted. Oracle 12c has established two innovative roles, the AUDIT_ADMIN, and the AUDIT _VIEWER.

Original source

To perform the auditing, user must be granted with the appropriate system privileges AUDIT ROLES in Oracle 12c - AUDIT_ADMIN and AUDIT_VIEWER

2

Student paper

“These two new roles support Unified Auditing which is managed by creating and enabling audit policies” (Spyker, 2017).

Original source

Unified Auditing is managed by creating and enabling audit policies

3

Student paper

The use of Unified Auditing keeps track of all audit data in a single audit trail.

Original source

All audit data is found in UNIFIED_AUDIT_TRAIL view

2

Student paper

On the other hand, AUDIT_ADMIN helps administrators to create, alter and enable audit policies.

Original source

AUDIT_ADMIN has privilege create, drop and alter audit policies

Student paper 64%

Student paper 63%

Student paper 75%

Student paper 63%

Student paper 100%

Student paper 100%

Student paper 100%

Student paper 100%

Student paper 100%

Student paper 100%

4

Student paper

With this role, therefore, it becomes easier for one to configure auditing as well as administering both unified and fine-grained audit policies.

Original source

The user with this role would be able to configure the auditing and also administer both the fine-grained audit policies and the unified audit policies

5

Student paper

Typically, this role is given out to the security administrators.

Original source

ADMIT_ADMIN role is granted typically to security administrators

6

Student paper

The audit data can immediately be written or it is also possible to queue it in the memory.

Original source

The audit data can be written immediately or it can also be queued in the memory

7

Student paper

This has helped simplify the configuration of database auditing in Oracle 12c.

Original source

Unified Auditing in Oracle Database 12c

6

Student paper

M., & Murthy, U.

Original source

M., & Murthy, U

6

Student paper

Continuous auditing of database applications: An embedded audit module approach. In Continuous Auditing: Theory and Application (pp.

Original source

Continuous auditing of database applications An embedded audit module approach In Continuous Auditing Theory and Application (pp

6

Student paper

Emerald Publishing Limited.

Original source

Emerald Publishing Limited

8

Student paper

https://docs.oracle.com/en/database/ora cle/oracle-database/12.2/upgrd/unified- auditing-audit_admin-audit_viewer- changes.html#GUID-0867243D-4F4B- 49B4-A7A5-C5EA98F59172

Original source

https://docs.oracle.com/en/database/ora cle/oracle-database/12.2/upgrd/unified- auditing-audit_admin-audit_viewer- changes.html#GUID-0867243D-4F4B- 49B4-A7A5-C5EA98F59172 “

9

Student paper

http://www.dba86.com/docs/oracle/12.2/ DBSEG/introduction-to-auditing.htm

Original source

http://www.dba86.com/docs/oracle/12.2/ DBSEG/introduction-to-auditing.htm

10

Student paper

https://docs.oracle.com/database/121/T DPSG/GUID-BF747771-01D1-4BFB-8489- 08988E1181F6.htm#TDPSG50051

Original source

https://docs.oracle.com/database/121/T DPSG/GUID-BF747771-01D1-4BFB-8489- 08988E1181F6.htm#TDPSG50051