Re: grant create any directory to schema

From: Mladen Gogala <gogala.mladen_at_gmail.com>
Date: Tue, 22 Dec 2015 02:46:03 -0500
Message-ID: <5678FFBB.8030004_at_gmail.com>



On 12/21/2015 08:54 PM, Andrew Kerber wrote:
> Yes it will be. Unfortunately your average auditor doesn't have the
> skill set to understand whether or not it really is a security problem.
>
> Sent from my iPad

The auditors don't have skills to figure out real security problems, here we do fully agree, but they do have checklists, which make them a pain in the neck or lower and supplant their technical skills. My favorite recommendation by the auditors is not to use user SYS for backup but to create another user for that. Of course, before the advent of fairly badly messed up SYSBACKUP role in 12c, that meant creating another SYSDBA user. And having two different SYSDBA users, with two different passwords, is somehow more secure than having just one?
-- 
Mladen Gogala
Oracle DBA
http://mgogala.freehostia.com

--
http://www.freelists.org/webpage/oracle-l
Received on Tue Dec 22 2015 - 08:46:03 CET

Original text of this message