APPS, SYSADMIN, and oracle
Securing Generic Privileged Accounts
May 15, 2014
Mike Miller
Stephen Kost
Chief Security Officer
Chief Technology Officer
Integrigy Corporation
Integrigy Corporation
Phil Reimann
Director of Business Development
Integrigy Corporation
Agenda
Best Practices
Overview
1
2
EBS Privileged
Accounts
3
Q&A
4
Logging
Auditing &
Monitoring
5
About Integrigy
ERP Applications
Databases
Oracle E-Business Suite
Oracle, SQL Server, MySQL
Products
AppSentry
Services
Validates
Security
ERP Application and Database
Security Auditing Tool
AppDefend
Verify
Security
Ensure
Compliance
Security Assessments
Oracle EBS, OBIEE, Databases,
Sensitive Data, Penetration Testing
Compliance Assistance
SOX, PCI, HIPAA
Protects
Oracle EBS
Enterprise Application Firewall for the Oracle E-Business Suite
Build
Security
Security Design Services
Auditing, Encryption, DMZ
You
Agenda
Best Practices
Overview
1
2
EBS Privileged
Accounts
3
Q&A
4
Logging
Auditing &
Monitoring
5
{ generic privileged account } application, database, or operating system account used for administration by multiple people and has significant privileges
Generic Privileged Accounts
Oracle E-Business Suite is defined by generic privileged accounts in each layer of the technology stack
-
Multiple highly privileged accounts
Generic accounts that must be used to manage the application and database
Majority of all data breaches committed by insiders -
Some intentional
Most accidental
Oracle EBS Generic Privileged Accounts
Oracle
E-Business Suite
Oracle
Database
Operating
System
(Unix and Linux)
SYSADMIN seeded application accounts
APPS, APPLSYS
SYS, SYSTEM
Oracle EBS schemas (GL, AP, ...)
root oracle, applmgr
Generic Privileged Account Inter-Dependency