Chapter 4. Security Governance
In this chapter, we will talk to the Chief Security Officer of the company and get an understanding of his sense of security risks that the company faces and the security posture that it adopts. We will help him express his priorities and objectives in the form of a balanced scorecard and ensure that the objectives are in concert with the corporate strategy. We will show him how to limit the access to systems only to authorized users and how to ensure that such authorization is based on specific needs. We will show how some of the security policies limit the duties of any individual so that privileges required to commit a fraud are separated. Next, we will show how to follow the guidance for hardening the system. Finally, we will guide him through setting up the security incident management and security incident response through the capabilities provided in Oracle Service.
Note
Note that it is beyond the scope of this book to advise you on security for the...