Hello,
auditor complained settings of audit parameters in oracle 11, especially audit_sys_operations=FALSE and audit_syslog_level=' '.
I found notes 1551504, 700548, 1963700, 1128663 etc with informations about technical configuration.
But I didn't found notes or links about the recommended setting by SAP and by advisors. Sometimes these recomendations differ, so that advisors recommend stronger security settings.
What are recommended settings for these audit parameters? Is it better to log auditfiles in database? Do logs have to be reported to the UNIX-syslog? And what is a good way to secure auditfiles in a folder, so that dbauser can still access for reading or creating?
Regards,
Julia
Request clarification before answering.
Hi,
But I didn't found notes or links about the recommended setting by SAP and by advisors. Sometimes these recomendations differ, so that advisors recommend stronger security settingsThere are lots of things that is considered and then recommended.
You should understand this.
From your side, you start by considering your environment and standard recommendations.
Once you have the audit done, you have the results and scope for improvements.
For your other queries, you have notes supporting them and already my counterparts have stated on the same.
So, Cheers,
Divyanshu
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.