Title :
Database Vault: Enforcing Separation of Duties to Meet Regulatory Compliance Requirements
Author :
Fabry, Heinz-Wilhelm
Author_Institution :
ORACLE Deutschland GmbH, Dusseldorf
Abstract :
Summary form only given. Various regulatory or legal requirements - such as the payment card industry´s PCI-DSS or the European Union´s directive 95/46/EC on the protection of personal data - limit access to certain data only to those who have a need to know. This has implications for all current database systems as these systems are being administered by database administrators who traditionally have access to all data at all times. This presentation outlines how database vault - a new so-called option for the Oracle database - allows for the separation of duties within a database e.g. by separating data management from user management, by taking any critical data out of reach of the database administrator, or by tying the execution of SQL statements to flexible limitations such as the 4 eyes principle.
Keywords :
database management systems; finance; Oracle database; PCI-DSS; SQL; database vault; payment card industry; regulatory compliance requirements; Database systems; Eyes; Law; Legal factors; Marketing and sales; Protection;
Conference_Titel :
Enterprise Distributed Object Computing Conference, 2008. EDOC '08. 12th International IEEE
Conference_Location :
Munich
Print_ISBN :
978-0-7695-3373-5
DOI :
10.1109/EDOC.2008.63