Skip to content

Commit 707cce8

Browse files
authored
Pull request to update WMS 700 and LiveLabs #3733: Be a Data Security Superhero with Oracle Data Safe (#364)
* removal of images using caps removal of images using caps * Updates for Cloud World 2025 * cloud world additions * typos * Text updates based on Bettina's feedback * Updates after run-through test
1 parent 00bf2ae commit 707cce8

21 files changed

+123
-151
lines changed

data-safe/access-environment/access-environment-ocw-sandbox.md

Lines changed: 4 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ In this lab, you will:
2323

2424
This lab assumes you have:
2525

26-
- Obtained an Oracle Cloud account and signed in to the Oracle Cloud Infrastructure Console at `https://cloud.oracle.com`
26+
- Reserved your environment for the HOL with the instructions given by the speaker.
2727

2828

2929
## Task 1: View your LiveLabs Sandbox reservation information and sign in
@@ -70,7 +70,7 @@ A database registered with Oracle Data Safe is referred to as a *target* databas
7070
3. Under **List scope**, browse to and select your compartment. Your registered target database is listed on the right.
7171

7272
- A target database with an **Active** status means that it is currently registered with Oracle Data Safe.
73-
- A target database with a **Deleted** status means that it is no longer registered with Oracle Data Safe. The listing is removed 45 days after the target database is deregistered.
73+
- A target database with a **Deleted** status means that it is no longer registered with Oracle Data Safe.
7474

7575
![Target databases page in OCI](images/target-databases-page-oci.png "Target databases page in OCI")
7676

@@ -87,7 +87,7 @@ A database registered with Oracle Data Safe is referred to as a *target* databas
8787

8888
- In Security center, you can access all the Oracle Data Safe features, including the dashboard, Security Assessment, User Assessment, Data Discovery, Data Masking, Activity Auditing, SQL Firewall, and Alerts.
8989
- When you register a target database, Oracle Data Safe automatically creates a security assessment and user assessment for you. That's why the **Security assessment**, **User assessment**, **Feature usage**, and **Operations summary** charts in the dashboard already have data.
90-
- During registration, Oracle Data Safe also discovers audit trails on your target database. That's why the **Audit trails** chart in the dashboard shows one audit trail with the status **In transition** for your Autonomous Database. Later you start this audit trail to collect audit data into Oracle Data Safe.
90+
- During registration, Oracle Data Safe also discovers audit trails on your target database. That's why the **Audit trails** chart in the dashboard shows one audit trail for your Autonomous Database. Later you start this audit trail to collect audit data into Oracle Data Safe.
9191

9292
![Initial Dashboard - security controls](images/dashboard-security-controls.png "Initial Dashboard - security controls")
9393

@@ -106,9 +106,6 @@ Database Actions provides a way for you to run SQL commands on your database. Th
106106

107107
3. If required, sign in as the `ADMIN` user.
108108

109-
- If a tenancy administrator provided you an Autonomous Database, obtain the password from that person.
110-
- If you are using an Oracle-provided environment, enter the database password provided to you.
111-
112109
4. Close the **SQL History** and **Warning** dialog boxes.
113110

114111
5. Review the interface. Here are the ways that you use Database Actions during the workshop:
@@ -138,4 +135,4 @@ You may now **proceed to the next lab**.
138135
## Acknowledgements
139136

140137
- **Author** - Jody Glover, Consulting User Assistance Developer, Database Development
141-
- **Last Updated By/Date** - Jody Glover, June 25, 2025
138+
- **Last Updated By/Date** - Jody Glover, August 1, 2025

data-safe/access-environment/access-environment-sandbox.md

Lines changed: 3 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@ A database registered with Oracle Data Safe is referred to as a *target* databas
6363
3. Under **List scope**, browse to and select your compartment. Your registered target database is listed on the right.
6464

6565
- A target database with an **Active** status means that it is currently registered with Oracle Data Safe.
66-
- A target database with a **Deleted** status means that it is no longer registered with Oracle Data Safe. The listing is removed 45 days after the target database is deregistered.
66+
- A target database with a **Deleted** status means that it is no longer registered with Oracle Data Safe. Cloud target databases are delisted after one day. Billable target databases are delisted after 45 days.
6767

6868
![Target databases page in OCI](images/target-databases-page-oci.png "Target databases page in OCI")
6969

@@ -78,7 +78,7 @@ A database registered with Oracle Data Safe is referred to as a *target* databas
7878

7979
- In Security center, you can access all the Oracle Data Safe features, including the dashboard, Security Assessment, User Assessment, Data Discovery, Data Masking, Activity Auditing, SQL Firewall, and Alerts.
8080
- When you register a target database, Oracle Data Safe automatically creates a security assessment and user assessment for you. That's why the **Security assessment**, **User assessment**, **Feature usage**, and **Operations summary** charts in the dashboard already have data.
81-
- During registration, Oracle Data Safe also discovers audit trails on your target database. That's why the **Audit trails** chart in the dashboard shows one audit trail with the status **In transition** for your Autonomous Database. Later you start this audit trail to collect audit data into Oracle Data Safe.
81+
- During registration, Oracle Data Safe also discovers audit trails on your target database. That's why the **Audit trails** chart in the dashboard shows one audit trail for your Autonomous Database. Later you start this audit trail to collect audit data into Oracle Data Safe.
8282

8383
![Initial Dashboard - security controls](images/dashboard-security-controls.png "Initial Dashboard - security controls")
8484

@@ -97,9 +97,6 @@ Database Actions provides a way for you to run SQL commands on your database. Th
9797

9898
3. If required, sign in as the `ADMIN` user.
9999

100-
- If a tenancy administrator provided you an Autonomous Database, obtain the password from that person.
101-
- If you are using an Oracle-provided environment, enter the database password provided to you.
102-
103100
4. Close any open dialog boxes.
104101

105102
5. Review the interface. Here are the ways that you use Database Actions during the workshop:
@@ -129,4 +126,4 @@ You may now **proceed to the next lab**.
129126
## Acknowledgements
130127

131128
- **Author** - Jody Glover, Consulting User Assistance Developer, Database Development
132-
- **Last Updated By/Date** - Jody Glover, May 5, 2025
129+
- **Last Updated By/Date** - Jody Glover, August 1, 2025

data-safe/assess-database-configurations/assess-database-configurations-ocw.md

Lines changed: 10 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -58,25 +58,19 @@ This lab assumes you have:
5858

5959
![Latest security assessment assessment summary tab](images/latest-sa-assessment-summary-tab.png "Latest security assessment assessment summary tab")
6060

61-
6. To view details about the security assessment itself, click the **Assessment information** tab.
62-
63-
- Details include assessment name, OCID, compartment to which the assessment was saved, target database name, target database version, assessment date and time, schedule, name of the baseline assessment (if one is set), and whether the assessment complies with the baseline (Yes, No, or No baseline set).
64-
65-
![Latest security assessment assessment information tab](images/latest-sa-assessment-information-tab2.png "Latest security assessment assessment information tab")
66-
67-
7. Scroll down and view the **Assessment details** section.
61+
6. Scroll down and view the **Assessment details** section.
6862

6963
- This section shows you all the findings for each risk category.
7064
- Risks are color-coded to help you easily identify categories that have high risk findings (red).
7165
- The high risk findings listed under **Privileges and Roles** were introduced when you ran the SQL script to populate your target database with sample data.
7266

7367
![Latest Security Assessment Assessment details section](images/latest-sa-assessment-details-section.png "Latest Security Assessment Assessment details section")
7468

75-
8. Under **Filters by risks** on the left, notice that you can select the risk levels that you want displayed. Also notice on the left that you can filter by references.
69+
7. Under **Filters by risks** on the left, notice that you can select the risk levels that you want displayed. Also notice on the left that you can filter by references.
7670

7771
![Security Assessment filters](images/sa-filters.png "Security Assessment filters")
7872

79-
9. On the right, expand categories and review the findings.
73+
8. On the right, expand categories and review the findings.
8074

8175
- Each finding shows you the status (risk level), a summary of the finding, details about the finding, remarks to help you to mitigate the risk, and references - whether a finding is recommended by the Center for Internet Security (**CIS**), European Union's General Data Protection Regulation (**EU GDPR**), Security Technical Implementation Guide (**DISA STIG**), and/or **Oracle best practices**. These references make it easy for you to identify the recommended security controls.
8276
- In the example below, the **Transparent Data Encryption** finding has three references: **Oracle Best Practices**, **DISA STIG**, and **GDPR**.
@@ -86,7 +80,7 @@ This lab assumes you have:
8680

8781
## Task 2: Set the latest assessment as the baseline assessment
8882

89-
A baseline assessment shows you data for all your target databases in a selected compartment at a given point in time. However, because we are only dealing with one target database in your compartment, the baseline assessment shows data for only one target database.
83+
A baseline assessment shows you data for all your target databases in a selected compartment at a given point in time. However, because we are only dealing with one target database in your compartment, the baseline assessment shows data for only one target database. Let’s assume that we are okay with the current configuration and we want to set it as our baseline. New assessments are then automatically compared to the baseline.
9084

9185
1. At the top of the page, click **Set as baseline**.
9286

@@ -103,7 +97,7 @@ A baseline assessment shows you data for all your target databases in a selected
10397

10498
## Task 3: Create a risk on the target database
10599

106-
In this task, you issue a `GRANT` command on your target database so that later, when you refresh the latest security assessment, you can compare assessments.
100+
In this task, you manually create a new configuration risk on your database by issuing a `GRANT` command. Later, when you refresh the latest security assessment, you can compare assessments.
107101

108102
1. Access the SQL worksheet in Database Actions. If your session has expired, sign in again as the `ADMIN` user.
109103

@@ -148,12 +142,13 @@ In this task, you issue a `GRANT` command on your target database so that later,
148142
149143
## Task 5: Compare your assessment with the baseline
150144
151-
1. With the latest security assessment displayed, under **Resources** on the left, click **Compare with baseline**. Oracle Data Safe automatically begins processing the comparison.
145+
1. With the latest security assessment displayed, under **Resources** on the left, click **Compare with baseline**.
152146
153-
If you navigated away from the latest security assessment, you can return to it by doing the following: Click **Security assessment** in the breadcrumb. Click the **Target summary** tab. Click **View report** for your target database.
147+
2. From the **Baseline** drop-down list, select your baseline. Oracle Data Safe automatically begins processing the comparison.
154148
149+
If you navigated away from the latest security assessment, you can return to it by doing the following: Click **Security assessment** in the breadcrumb. Click the **Target summary** tab. Click **View report** for your target database.
155150
156-
2. When the comparison operation is completed, scroll down the page to the **Comparison with baseline** section and review the information.
151+
3. When the comparison operation is completed, scroll down the page to the **Comparison with baseline** section and review the information.
157152
158153
- Review the number of findings per risk category for each risk level. Categories include **User accounts**, **Privileges and roles**, **Authorization control**, **Data encryption**, **Fine-grained access control**, **Auditing**, and **Database configuration**.
159154
- You can identify where the changes have occurred on your target database by viewing cells that contain the word **Modified**. The number represents the total count of new, remediated, and modified risks on the target database.
@@ -174,4 +169,4 @@ You may now **proceed to the next lab**.
174169
## Acknowledgements
175170
176171
* **Author** - Jody Glover, Consulting User Assistance Developer, Database Development
177-
* **Last Updated By/Date** - Jody Glover, June 25, 2025
172+
* **Last Updated By/Date** - Jody Glover, August 1, 2025

data-safe/assess-database-configurations/assess-database-configurations.md

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -135,7 +135,7 @@ You can defer or change the risk level of a risk finding. In this task, defer th
135135

136136
## Task 4: Set the latest assessment as the baseline assessment
137137

138-
A baseline assessment shows you data for all your target databases in a selected compartment at a given point in time. However, because we are only dealing with one target database in your compartment, the baseline assessment shows data for only one target database.
138+
A baseline assessment shows you data for all your target databases in a selected compartment at a given point in time. However, because we are only dealing with one target database in your compartment, the baseline assessment shows data for only one target database. Let’s assume that we are okay with the current configuration and we want to set it as our baseline. New assessments are then automatically compared to the baseline.
139139

140140
1. At the top of the page, click **Set as baseline**.
141141

@@ -152,7 +152,7 @@ A baseline assessment shows you data for all your target databases in a selected
152152

153153
## Task 5: Create a risk on the target database
154154

155-
In this task, you issue a `GRANT` command on your target database so that later, when you refresh the latest security assessment, you can compare assessments.
155+
In this task, you manually create a new configuration risk on your database by issuing a `GRANT` command. Later, when you refresh the latest security assessment, you can compare assessments.
156156

157157
1. Access the SQL worksheet in Database Actions. If your session has expired, sign in again as the `ADMIN` user.
158158

@@ -197,12 +197,13 @@ In this task, you issue a `GRANT` command on your target database so that later,
197197
198198
## Task 7: Compare your assessment with the baseline
199199
200-
1. With the latest security assessment displayed, under **Resources** on the left, click **Compare with baseline**. Oracle Data Safe automatically begins processing the comparison.
200+
1. With the latest security assessment displayed, under **Resources** on the left, click **Compare with baseline**.
201201
202-
If you navigated away from the latest security assessment, you can return to it by doing the following: Click **Security assessment** in the breadcrumb. Click the **Target summary** tab. Click **View report** for your target database.
202+
2. From the **Baseline** drop-down list, select your baseline. Oracle Data Safe automatically begins processing the comparison.
203203
204+
If you navigated away from the latest security assessment, you can return to it by doing the following: Click **Security assessment** in the breadcrumb. Click the **Target summary** tab. Click **View report** for your target database.
204205
205-
2. When the comparison operation is completed, scroll down the page to the **Comparison with baseline** section and review the information.
206+
3. When the comparison operation is completed, scroll down the page to the **Comparison with baseline** section and review the information.
206207
207208
- Review the number of findings per risk category for each risk level. Categories include **User accounts**, **Privileges and roles**, **Authorization control**, **Data encryption**, **Fine-grained access control**, **Auditing**, and **Database configuration**.
208209
- You can identify where the changes have occurred on your target database by viewing cells that contain the word **Modified**. The number represents the total count of new, remediated, and modified risks on the target database.
@@ -223,4 +224,4 @@ You may now **proceed to the next lab**.
223224
## Acknowledgements
224225
225226
* **Author** - Jody Glover, Consulting User Assistance Developer, Database Development
226-
* **Last Updated By/Date** - Jody Glover, May 5, 2025
227+
* **Last Updated By/Date** - Jody Glover, August 1, 2025

data-safe/assess-database-users/assess-database-users-ocw.md

Lines changed: 8 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22

33
## Introduction
44

5-
User Assessment helps you assess the security of your database users and identify potential high risk users. By default, Oracle Data Safe automatically generates user assessments for your target databases and stores them in the Assessment History. You can analyze assessment data across all your target databases and for each target database. You can monitor security drift on your target databases by comparing the latest assessment to a baseline or to another assessment.
5+
User Assessment helps you assess the security of your database users and identify potential high risk users. This allows you to review the potential risk to your data in case any of your user accounts get compromised or go rogue. By default, Oracle Data Safe automatically generates user assessments for your target databases and stores them in the Assessment History. You can analyze assessment data across all your target databases and for each target database. You can monitor user or entitlement changes on your target databases by comparing the latest assessment to a baseline or to another assessment.
66

77
In this lab, you explore User Assessment.
88

@@ -35,7 +35,7 @@ This lab assumes you have:
3535

3636
## Task 1: Analyze users in the latest user assessment
3737

38-
The latest user assessment is the one that was automatically generated by Oracle Data Safe when you registered your target database.
38+
The latest user assessment is the one that was automatically generated by Oracle Data Safe when your target database was registered.
3939

4040
1. In the breadcrumb at the top of the page, click **Security center**. On the left, click **User assessment**.
4141

@@ -82,11 +82,11 @@ The latest user assessment is the one that was automatically generated by Oracle
8282
- User name
8383
- User profile
8484
- User type (for example, PRIVILEGED)
85-
- Status (for example, OPEN)
86-
- Potential risk (for example, CRITICAL) - Hover over the **i** to view what constitutes a critical risk user.
87-
- Last login date and time
8885
- Date and time when the user was created
86+
- Potential risk (for example, CRITICAL) - Hover over the **i** to view what constitutes a critical risk user.
87+
- Status (for example, OPEN)
8988
- Date and time when the password was last changed
89+
- Last login date and time
9090
- Password expiry date
9191
- Privileged roles (the Admin roles granted to the user)
9292
- Roles: Expand **All roles** to view all the roles granted to the user
@@ -153,11 +153,8 @@ You can select a user assessment to compare with the latest user assessment. Wit
153153
154154
4. From the **Select assessment** drop-down list, select the initial assessment for your target database. As soon as you select it, the comparison operation is started.
155155
156-
5. Review the results.
157-
158-
- There is a new user added and a user deleted. The new user finding is identified as a potential **CRITICAL** risk.
159-
- There are user grants modified by the `DS$ADMIN` user. This finding is also identified as a potential **CRITICAL** risk.
160-
156+
5. Review the results. A new user is added and a user is deleted. The new user finding is identified as a potential **CRITICAL** risk.
157+
161158
![User Assessment Comparison report](images/ua-comparison-report3.png "User Assessment Comparison report")
162159
163160
6. In the **Comparison results** column, click one of the **Open details** links to view more information.
@@ -178,4 +175,4 @@ You may now **proceed to the next lab**.
178175
## Acknowledgements
179176
180177
* **Author** - Jody Glover, Consulting User Assistance Developer, Database Development
181-
* **Last Updated By/Date** - Jody Glover, June 24, 2025
178+
* **Last Updated By/Date** - Jody Glover, August 1, 2025

0 commit comments

Comments
 (0)