<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.securityprocedure.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Oracle Finance</title>
 <link>http://www.securityprocedure.com/tag/oracle-finance</link>
 <description>The taxonomy view with a depth of 0.</description>
 <language>en</language>
<item>
 <title>Oracle Security, audit procedure and checklist, 5 basic controls</title>
 <link>http://www.securityprocedure.com/oracle-security-audit-procedure-and-checklist-5-basic-controls</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img177.imageshack.us/img177/1718/oraclelogoyq9.jpg&quot;&gt;&lt;br /&gt;
Need to audit an Oracle Database or Application; here is simple guidance, 5 basic controls that you should monitor.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;1. Password Management&lt;br /&gt;&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Default Passwords, should be changed&lt;/li&gt;
&lt;li&gt;Required Passwords, should be enabled&lt;/li&gt;
&lt;li&gt;Password Composition, should be contain character, numeric and combination&lt;/li&gt;
&lt;li&gt;Password Expiration, should be expire within period e.g. 30 days&lt;/li&gt;
&lt;li&gt;Password History, should be not repeated after period e.g. 12 password.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;2. User Management&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Administrator Account, should be secured. All administrator account should be stated clearly and who&amp;rsquo;s responsible with it.&lt;/li&gt;
&lt;li&gt;Default user account, should be removed or deactivated&lt;/li&gt;
&lt;li&gt;Vendor / third party account, should be monitored&lt;/li&gt;
&lt;li&gt;Dormant Account, should be maintained.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;3. Security Feature&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/oracle-security-audit-procedure-and-checklist-5-basic-controls&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/oracle-security-audit-procedure-and-checklist-5-basic-controls#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/oracle-finance">Oracle Finance</category>
 <category domain="http://www.securityprocedure.com/tag/procedures">Procedures</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <pubDate>Tue, 18 Mar 2008 04:01:20 -0500</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">87 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Why SAP is better than Oracle Finance in Security Perspective: part 1</title>
 <link>http://www.securityprocedure.com/why-sap-better-oracle-finance-security-perspective-part-1</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img144.imageshack.us/img144/3774/sapof7.png&quot; HEIGHT=&quot;70&quot;&gt;&lt;IMG SRC=&quot;http://img177.imageshack.us/img177/1718/oraclelogoyq9.jpg&quot;&gt;&lt;br /&gt;
There are a lot of comparison between SAP and Oracle Finance available nowadays; this article is focusing the comparison in security or audit perspective.&lt;/p&gt;
&lt;p&gt;&lt;H3&gt;1. Security Configuration&lt;/H3&gt;SAP stored their security configuration in application security level; Oracle Finance stored their security configuration in database security level. Storing configuration in application security level means that we could added the security level also in database configuration. So SAP will have two times higher security level than Oracle Finance.&lt;/p&gt;
&lt;p&gt;Here is audit procedure to check both of Oracle Finance and SAP R/3 security configuration.&lt;/p&gt;
&lt;p&gt;&lt;B&gt;SAP R/3 Procedure: &lt;/B&gt;&lt;br /&gt;
Execute Transaction Code SA38&lt;br /&gt;
Run report RSPARAM&lt;/p&gt;
&lt;PRE&gt;login/failed_user_auto_unlock           
login/fails_to_session_end              
login/fails_to_user_lock                
login/min_password_lng                  
login/multi_login_users                 
login/no_automatic_user_sapstar         
login/password_change_for_SSO           
login/password_expiration_time          
login/password_logon_usergroup          
login/password_max_new_valid            
login/password_max_reset_valid.          
&lt;/PRE&gt;&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/why-sap-better-oracle-finance-security-perspective-part-1&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/why-sap-better-oracle-finance-security-perspective-part-1#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/oracle-finance">Oracle Finance</category>
 <category domain="http://www.securityprocedure.com/tag/procedures">Procedures</category>
 <category domain="http://www.securityprocedure.com/tag/sap">SAP</category>
 <pubDate>Fri, 14 Mar 2008 20:39:18 -0500</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">79 at http://www.securityprocedure.com</guid>
</item>
</channel>
</rss>
