Free Trial

Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.


  • Create BookmarkCreate Bookmark
  • Create Note or TagCreate Note or Tag
  • PrintPrint
Share this Page URL
Help

6 Applied Database Vault for Custom Appl... > Establish DBV Secure Application Rol...

Establish DBV Secure Application Roles from Conditions

DBV SARs can be used when you have operations that are highly sensitive or potentially risky but not used very frequently. Another useful scenario for using DBV SARs are when you have a connection pool account that is used to assert multiple roles with different privileges and want the roles used only under the correction conditions. This approach reduces the risk of an alternative that would require granting several sets of roles directly to the account and creating an overprivileged account.

In Chapter 5 we presented an example of a highly sensitive role that enabled the archiving of sales data only during the system maintenance window. This is an example of a highly sensitive or potentially risky operation that is used infrequently. Creating a DBV secure application role for the oper_dba_0101 role we presented earlier may not make sense if we expect a user such as jean_oper_dba to be managing the database on a daily basis and using these privileges frequently.


  

You are currently reading a PREVIEW of this book.

                                                                                        

Get instant access to over
$1 million worth of books and videos.

  

Start a Free Trial