DocumentCode
2969508
Title
Database Vault: Enforcing Separation of Duties to Meet Regulatory Compliance Requirements
Author
Fabry, Heinz-Wilhelm
Author_Institution
ORACLE Deutschland GmbH, Dusseldorf
fYear
2008
fDate
15-19 Sept. 2008
Abstract
Summary form only given. Various regulatory or legal requirements - such as the payment card industry´s PCI-DSS or the European Union´s directive 95/46/EC on the protection of personal data - limit access to certain data only to those who have a need to know. This has implications for all current database systems as these systems are being administered by database administrators who traditionally have access to all data at all times. This presentation outlines how database vault - a new so-called option for the Oracle database - allows for the separation of duties within a database e.g. by separating data management from user management, by taking any critical data out of reach of the database administrator, or by tying the execution of SQL statements to flexible limitations such as the 4 eyes principle.
Keywords
database management systems; finance; Oracle database; PCI-DSS; SQL; database vault; payment card industry; regulatory compliance requirements; Database systems; Eyes; Law; Legal factors; Marketing and sales; Protection;
fLanguage
English
Publisher
ieee
Conference_Titel
Enterprise Distributed Object Computing Conference, 2008. EDOC '08. 12th International IEEE
Conference_Location
Munich
ISSN
1541-7719
Print_ISBN
978-0-7695-3373-5
Type
conf
DOI
10.1109/EDOC.2008.63
Filename
4634736
Link To Document