tailieunhanh - Applied Oracle Security: Developing Secure Database and Middleware Environments- P31
Applied Oracle Security: Developing Secure Database and Middleware Environments- P31:Computer security is a field of study that continues to undergo significant changes at an extremely fast pace. As a result of research combined with increases in computing capacity, computer security has reached what many consider to be “early adulthood.” From advances in encryption and encryption devices to identity management and enterprise auditing, the computer security field is as vast and complex as it is sophisticated and powerful | 274 Part II Oracle Database Vault diego_dbvmgr@aos -- conditions to be true diego_dbvmgr@aos BEGIN rule_set_name Add Sales Cost Allowed description Checks to authorize creation of Sales Cost records. enabled eval_options audit_options fail_options fail_message NULL fail_code NULL handler_options handler NULL END PL SQL procedure successfully completed. diego_dbvmgr@aos add our Sales department manager rule diego_dbvmgr@aos BEGIN rule_set_name Add Sales Cost Allowed rule_name Is Sales Department Manager END PL SQL procedure successfully completed. diego_dbvmgr@aos -- add the outside of the system maintenance window rule diego_dbvmgr@aos BEGIN rule_set_name Add Sales Cost Allowed rule_name Outside System Maintenance Window END PL SQL procedure successfully completed. diego_dbvmgr@aos add the Sales management package check rule diego_dbvmgr@aos BEGIN rule_set_name Add Sales Cost Allowed rule_name Called From Sales Transaction Package END PL SQL procedure successfully completed. Finally we create our DBV command rule on the INSERT SQL command for the table and test its effectiveness for both the JRUSSEL and PTUCKER accounts Chapter 6 Applied Database Vault for Custom Applications 275 diego_dbvmgr@aos BEGIN command_rule command INSERT rule_set_name Add Sales Cost Allowed object_owner SH object_name COSTS enabled END PL SQL procedure successfully completed. diego_dbvmgr@aos CONNECT jrussel Enter password Connected. jrussel@aos -- direct INSERT on should fail because it is jrussel@aos -- not issued from the sales management package jrussel@aos INSERT INTO prod_id time_id promo_id channel_id unit_cost unit_price SELECT .
đang nạp các trang xem trước