• DocumentCode
    2969508
  • Title

    Database Vault: Enforcing Separation of Duties to Meet Regulatory Compliance Requirements

  • Author

    Fabry, Heinz-Wilhelm

  • Author_Institution
    ORACLE Deutschland GmbH, Dusseldorf
  • fYear
    2008
  • fDate
    15-19 Sept. 2008
  • Abstract
    Summary form only given. Various regulatory or legal requirements - such as the payment card industry´s PCI-DSS or the European Union´s directive 95/46/EC on the protection of personal data - limit access to certain data only to those who have a need to know. This has implications for all current database systems as these systems are being administered by database administrators who traditionally have access to all data at all times. This presentation outlines how database vault - a new so-called option for the Oracle database - allows for the separation of duties within a database e.g. by separating data management from user management, by taking any critical data out of reach of the database administrator, or by tying the execution of SQL statements to flexible limitations such as the 4 eyes principle.
  • Keywords
    database management systems; finance; Oracle database; PCI-DSS; SQL; database vault; payment card industry; regulatory compliance requirements; Database systems; Eyes; Law; Legal factors; Marketing and sales; Protection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Enterprise Distributed Object Computing Conference, 2008. EDOC '08. 12th International IEEE
  • Conference_Location
    Munich
  • ISSN
    1541-7719
  • Print_ISBN
    978-0-7695-3373-5
  • Type

    conf

  • DOI
    10.1109/EDOC.2008.63
  • Filename
    4634736