Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 26 visitors online    

Oracle Database Security Audit Training Course [ 2 Days ]

This course teaches the delegates how to confidently perform a security audit on an Oracle database. The course gets the delegates up to speed on the reasons Oracle databases are invariably insecure. Everyone is brought up to the same level in terms of where to look, what to look for and why. The course shows how a security audit is planned, how to prepare yourself for it, your staff and your environments. The course is aimed at the fundamentals of how to review a database and why and does not focus on simply running tools. It is important to understand why something is an issue, to understand how to check that its an issue and importantly understand the implications in respect to your own databases and applications before using pre-built or commercial tools.

The course has been designed by Pete Finnigan and is up to date using all supported versions of Oracle from 9iR2 through Oracle 11g. The course is run on your own site and is over two days and includes the following topics:

  • Background to key database files, structures, configurations and files relative to security
  • Oracle security tools, checklists and more
  • Why audit an Oracle database
  • Exploiting Oracle, SQL Injection, configuration, escalation of privilege and more
  • Planning an audit
  • Setting up for an audit, gathering tools, prepping laptop, people, access
  • Starting the audit
  • Software installed, versions and attack surface
  • Enumerating users, password strength and more
  • Assessing users, privileges and RBAC
  • Auditing the Oracle database association with the file system
  • Audit Oracle networking
  • Audit the database configuration
  • Specialist considerations, Credit cards, personally identifiable data and more
  • Review the audit trail
  • Data analysis, vulnerability assessment
  • Document findings, develop a policy and deciding what to fix
  • A look at some of the automated tools

The course is delivered by Pete Finnigan, a principal consultant with years of real world experience in auditing and securing customers Oracle databases. Pete is also well known for writing and presenting extensively in the area of Oracle security. The course includes the slides and delegate notes and is delivered on customers sites.

This course is offered at a fixed price for up to 8 students, any additional students can be added for a modest additional cost. Please email info@petefinnigan.com to book this training course, to discuss your individual requirements or to discuss partnering with PeteFinnigan.com Limited. We will be pleased to hear from you.