Posts

Oracle Database Vault: A Complete Hands-On Guide to Locking Down Privileged Access (CDB, PDB, Realms & Unified Audit)

Image
Locking Down the Database from the Inside: My Hands-On Implementation of Oracle Database Vault Munish Kumar Karna  |  Senior Database Solution Architect & Oracle DBA Every DBA eventually confronts an uncomfortable truth: the biggest risk to a “secure” database is often the person with the keys to it. Firewalls, network segmentation, and encryption all assume the threat is outside the perimeter — but SYSDBA, SYSTEM, and other privileged accounts sit squarely inside it. Over the past few weeks I implemented Oracle Database Vault end-to-end — from installing the option to enforcing a working security Realm with full audit visibility — and I want to walk through exactly how it was done, screenshots and SQL included, for anyone evaluating this for their own environment. Why Oracle Database Vault Matters Oracle Database Vault addresses insider threats and privileged account abuse by restricting access inside the database itself. A few reasons it belongs in any seriou...

Row-Level Security, Done Right: My Oracle Label Security Rollout Across Nepal's 7 Provinces

Image
Row-Level Security, Done Right: My Oracle Label Security Rollout Across Nepal's 7 Provinces Oracle Label Security | Case Study Row-Level Security, Done Right: My Oracle Label Security Rollout Across Nepal's 7 Provinces How I used Oracle Label Security to enforce province- and department-level data access across Nepal's 7 provinces Munish Kumar Karna - DBA The Business Problem A national organization operating across all 7 provinces of Nepal needed a single, shared database — but with very different visibility rules depending on who was looking at it. Executive leadership needed a complete, nationwide view. Province-level managers needed full visibility into their own province, but nothing outside it. And functional staff (HR, IT, Marketing, Finance) needed to see only their own department's records within their own province. Rather than maintaining separate schemas, views, or application-level filters for every combination of role and province, ...