1Copyright © 2011, Oracle and/or its affiliates. All rights reserved.
2 The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Oracle’s products remains at the sole discretion of Oracle.
3Copyright © 2011, Oracle and/or its affiliates. All rights reserved. Who are we? Applications Product Security –Eric Bing –Erik Graversen –Robert Armstrong
4Copyright © 2011, Oracle and/or its affiliates. All rights reserved. What do we do? External –Secure Configuration –Security Certifications (DB Vault, TDE, ASO, Masking…) –Security vulnerabilities and Critical Patch Updates Internal –Coordinate the Oracle Software Security Assurance Program (OSSA)
5Copyright © 2011, Oracle and/or its affiliates. All rights reserved. Q&A
6Copyright © 2011, Oracle and/or its affiliates. All rights reserved. What’s New – Secure Configuration Security Related News New Secure Config Guides (11i , ) –Stricter Profile Option Settings [FND_%VALIDATION] ( ) (Note ) –Non-Reversible password hashing for FND_USERs –AFPASSWD is a FNDCPASS replacement (12.1.3) –AdminDesktop Utility –DO3475 “PUBLIC Grants on Restricted Packages” Certified with Transparent Data Encryption (Col & TS)
7Copyright © 2011, Oracle and/or its affiliates. All rights reserved. What’s New – Separation of Duties Security Related News Sensitive Administrator Functionality (Note ) Using E-Business Suite Plug-In (ACP) for SOD during patching (Note ) Start/Stop CM without Apps password (12.1.3) Certified with Database Vault
8Copyright © 2011, Oracle and/or its affiliates. All rights reserved.