Oracle Data Control Language (DCL) Versions All |
---|
Security Advisory | ||||||||||||||||||
DCL, in and of itself, is not a security risk. But, controlling and monitoring two elements of DCL, is critically important to creating and maintaining a secure environment. Use the table below to better identify those DCL statements of concern; and why. |
||||||||||||||||||
|
||||||||||||||||||
To address issues related to GRANT and REVOKE statements the best line of defense is DDL triggers. Auditing in this situation is slightly better than useless but not by much as auditing GRANT and REVOKE statements will tell you minutes, hours, or days, what happened that should not have happened and by then it will likely be too late to do much other than issue an apology to your customers. The other issue with auditing, from the standpoint of security, is that it is most often incapable of telling the difference between an appropriate GRANT and an inappropriate GRANT and thus often relies on a marginally trained member of a security group to raise an alarm. |
Related Topics |
Data Definition Language (DDL) |
DDL Event Triggers |