1copyright © 2011, oracle and/or its affiliates. all rights reserved

8
1 Copyright © 2011, Oracle and/or its affiliates. All rights reserved.

Upload: mary-hunter

Post on 04-Jan-2016

212 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: 1Copyright © 2011, Oracle and/or its affiliates. All rights reserved

1 Copyright © 2011, Oracle and/or its affiliates. All rights reserved.

Page 2: 1Copyright © 2011, Oracle and/or its affiliates. All rights reserved

2 Copyright © 2011, Oracle and/or its affiliates. All rights reserved.

The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Oracle’s products remains at the sole discretion of Oracle.

Page 3: 1Copyright © 2011, Oracle and/or its affiliates. All rights reserved

3 Copyright © 2011, Oracle and/or its affiliates. All rights reserved.

Who are we?

• Applications Product Security– Eric Bing– Erik Graversen– Robert Armstrong

Page 4: 1Copyright © 2011, Oracle and/or its affiliates. All rights reserved

4 Copyright © 2011, Oracle and/or its affiliates. All rights reserved.

What do we do?

• External– Secure Configuration– Security Certifications (DB Vault, TDE, ASO, Masking…)– Security vulnerabilities and Critical Patch Updates

• Internal– Coordinate the Oracle Software Security Assurance Program

(OSSA)

Page 5: 1Copyright © 2011, Oracle and/or its affiliates. All rights reserved

5 Copyright © 2011, Oracle and/or its affiliates. All rights reserved.

Q&A

Page 6: 1Copyright © 2011, Oracle and/or its affiliates. All rights reserved

6 Copyright © 2011, Oracle and/or its affiliates. All rights reserved.

What’s New – Secure ConfigurationSecurity Related News

• New Secure Config Guides (11i - 189367.1 , 12 - 403537.1)– Stricter Profile Option Settings [FND_%VALIDATION] (11.5.10.2+)

(Note 946372.1)– Non-Reversible password hashing for FND_USERs– AFPASSWD is a FNDCPASS replacement (12.1.3)– AdminDesktop Utility– DO3475 “PUBLIC Grants on Restricted Packages”

• Certified with Transparent Data Encryption (Col & TS)

Page 7: 1Copyright © 2011, Oracle and/or its affiliates. All rights reserved

7 Copyright © 2011, Oracle and/or its affiliates. All rights reserved.

What’s New – Separation of DutiesSecurity Related News

• Sensitive Administrator Functionality (Note 1334930.1)

• Using E-Business Suite Plug-In (ACP) for SOD during patching (Note 1363260.1)

• Start/Stop CM without Apps password (12.1.3)

• Certified with Database Vault

Page 8: 1Copyright © 2011, Oracle and/or its affiliates. All rights reserved

8 Copyright © 2011, Oracle and/or its affiliates. All rights reserved.