|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/demystifying-oracle-database-securityon-prem-oracle-cloud/
课程评论:没有评论
本课程旨在揭开 On-Premises 和 Oracle Cloud Infrastructure (OCI) 中 Oracle 数据库安全的面纱。通过学习,您将了解 21 世纪十大数据安全泄露事件,并深入理解主要的数据库安全威胁、数据库安全基础以及 Oracle 极致安全架构 (MSA)。 课程将通过三个环境的搭建和实践来巩固学习: 1. **Oracle On-Premises 环境**(虚拟机) 2. **Oracle 虚拟机数据库系统** 3. **Oracle 数据库即服务 (Autonomous Database, ADB)** **核心内容模块:** * **Oracle Database Vault:** * 学习其功能、组件以及最重要的“职责分离”原则。 * 通过演示了解如何在 CDB 和 PDB 中配置 Database Vault。 * 理解 Realm 的概念并实际配置自定义 Realm。 * 处理 DBA 导出受 Realm 保护的 Schema 的权限用例。 * 将 Database Vault 应用到 Oracle 数据库即服务 (ADB) 中。 * **数据加密:** * **静态数据加密 (TDE):** 深入理解 TDE 密钥架构以及 Oracle Key Vault 的概念。通过 `strings` 命令展示未加密数据,并实施 TDE 加密静态数据。 * **传输中数据加密 (NNE):** 演示在检查网络数据包时数据是否明文传输,并在实施 NNE 后实现传输中数据的加密。 * **数据库安全评估工具 (DBSAT):** * 学习 DBSAT 的组件和工具。 * 完成 DBSAT Collector 和 Reporter 的演示。 * 理解和分析 DBSAT 生成的各类输出文件。 * **Oracle 统一审计 (Unified Auditing):** * 对比传统审计与统一审计的差异。 * 探索开箱即用的统一审计策略,并配置统一审计以纯模式运行。 * 创建自定义审计策略。 * **Oracle Data Safe:** * 将 Data Safe 作为统一管理数据库安全性的平台,适用于 On-Premises、VM/BM 数据库系统和 Autonomous Database。 * 通过 Data Safe 演示实现:数据库安全评估、用户评估、敏感数据发现和数据脱敏。 本课程由 OCM & OCI 架构师 Kshitij Joy 主讲,旨在为您提供一套全面的 Oracle 数据库安全知识体系。
With the advent of Cloud Computing the biggest challenge that is being faced by the organizations is around Database Security. I understand companies ensure Oracle MAA (Maximum Availability Architecture) but trust me it's time to embrace Oracle MSA (Maximum Security Architecture). Through this course I will demystify the Oracle database security for On-Prem and Oracle Cloud Infrastructure (OCI).I will show the evidence of the Top 10 Data Security Breaches of 21st century. We will try and understand the Major Security Threats , Artefacts of Database Security and will give you a good understanding of Oracle Maximum Security Architecture.For our learning we shall build 3 environments:· Oracle On-Prem Environment on VM Machine· Oracle Virtual Machine DB System· Oracle Autonomous Database (ADB).We will start our learning with Oracle Database Vault , understand the features, components, Separation of Duties. We will perform some demos to understand how to configure Database Vault for CDB & PDB. We will understand the concept behind Realms and also configure our own realm. We will work on a couple of use cases regarding the permissions that need to be given to the DBA to export the schema protected by realms. We will also configure the Database Vault for Autonomous Databases as well.One of the most important requirements from the regulators is the Data Encryption which can be configured for Data at Rest using Transparent Data Encryption(TDE) and for Data in Transit using Native Network Encryption (NNE). We will go deep dive to understand TDE Key Architecture and the concept of Oracle Key vaults. I will perform strings command on the data files and show you that your Table's data is visible in clear text format and then will implement TDE and encrypt the data at rest. Same way I will show you that if you inspect the network packets the data in transit is available in clear text, once NNE is implemented the data in transit gets encrypted as well.Next we will move to assessment of Database security through Database Security Assessment Tool (DBSAT), We will learn the DBSAT Components, tools and perform demo for DBSAT collector / reporter and also understand and look at the different output files that are created by DBSAT.Another key architectural change for post 12c release was Oracle Unified Auditing, we will understand the comparison between the traditional vs Unified auditing. The Unified Auditing brings a number of policies which come out of box and are enabled by default. For our demos we will enable the unified auditing to run in pure mode , we will make use of the out of the box policies and also create our own customized policy.In the end we will move onto an amazing feature Oracle Data Safe which helps to bring entire database security under one umbrella. The Oracle Data Safe can be used for On-Prem database, VM / BM Database Systems and Autonomous Databases. Through Oracle Data Safe we will perform the demos to achieve Database Security Assessment, User Assessment , Data Sensitive Discovery and Data Masking.RegardsKshitij Joy (OCM & OCI Architect)DB Alchemist Academy