| |
 |
|
Oracle Tips by Burleson |
Chapter 2 Introduction
to Oracle Security
which will allow her to insert, update, delete,
and select all claims tables and only select from the lookup tables.
When another employee joins the pool of adjusters, he can also be
assigned this role. When Jane moves out of the claims adjustment
department to, say, human resources, this role can easily be revoked
in one statement, disallowing her access to the tables
instantaneously.
Use roles to assign groups of users the same
set of security privileges.
However, there are several security holes in a
role-based authorization model. The details of the role-based model,
with working examples and caveats, are explained in Chapter 4 under
General Security.
Profile-Based Security
The staff at Metropolitan Museum pays careful
attention to rules, which are enforced strictly to ensure the
security and safety of the visitors and the exhibits. One of the
rules, unpalatable to some visitors like John’s son, forbids running
in the museum for fear of hitting one of the exhibits. In other
words, younger visitors in particular are restricted on some of
their natural movements. However, persons such as security guards
and police officers may have to run in order to perform job tasks.
What differentiates these free roamers from the visitors with
restricted movement?
One factor is the role
they perform inside the museum - some are security guards and others
are visitors. However, note the difference in the nature of the
privilege - it's not about accessing an object like a particular
room or exhibit, it's about moving around at a
The above text is
an excerpt from:
Oracle Privacy Security Auditing
The
Final Word on Oracle Security
This is the only authoritative
book on Oracle Security, Oracle Privacy, and Oracle Auditing written
by two of the world’s leading Oracle Security experts.
This indispensable book is only $39.95 and has an
immediate download of working security scripts:
http://rampant-books.com/book_2003_2_audit.htm
|
Download your Oracle scripts now:
www.oracle-script.com
The
definitive Oracle Script collection for every Oracle professional DBA
|
|