
Monitoring Oracle E-Business Suite 8-19
Compliance Standards for Oracle E-Business Suite
The Oracle Enterprise Manager Compliance Management solution provides the
capability to define, customize, and manage Compliance Frameworks and Compliance
Standards. It also provides tools to evaluate targets and systems for compliance with
business best practices in terms of configuration, security, storage, and so on.
Compliance evaluation generates a score for a target which indicates how much the
target is compliant with the standard. Violation of a standard can be classified as
critical, warning or minor warning.
The management pack includes a set of compliance standards for Oracle E-Business
Suite security which will be associated to every Oracle E-Business Suite instance once it
is discovered. Evaluation will happen periodically which will ensure that the Oracle
E-Business Suite is configured in a secure way.
The following table lists details of the compliance standards shipped along with the
compliance rules associated with them.
Compliance Standards
Compliance Standard Rules mapped to the standard Severity
Profile Settings Check if all critical profiles are set correctly. Critical
Profile Settings Check if other profiles are set correctly. Warning
Profile Settings Check if no profile is missing. Critical
Change Default Passwords Checks if any database user with a default
password exists.
Critical
Change Default Passwords Checks if any application user with a default
password exists.
Critical
Secure APPLSYSPUB Checks if there is any unwanted privilege in
the APPLSYSPUB account.
Warning
Use Secure Flag on DBC File Checks if server security is on. Warning
Migrate to Password Hash Checks if the setting for hashed passwords
are on.
Warning
Enable Application Tier Secure
Socket Layer (SSL)
Checks if Oracle E-Business Suite is
configured for HTTPS.
Warning
Kommentare zu diesen Handbüchern