<?xml version='1.0' encoding='iso-8859-1' ?><rss version="2.0"><channel><title>Oracle E-business (General)</title><link>http://www.checklist20.com/bestpractices.html</link><description>Oracle E-Business Suite is the most comprehensive suite of integrated, global business applications that provides: The most complete, integrated business intelligence portfolio, The most adaptable global business platform and The most customer-focused applications strategy</description><item><title>Practice Safe Cloning</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=243&amp;tn=Practice Safe Cloning</link><description>Many copies of production environments are created, a.k.a. cloning, for various purposes. These copies are typically used for performance test by DBAs or developers or to test upgrade/patching of the production database. Cloning of production envi ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=243&amp;tn=Practice Safe Cloning'>View More</a>]]></description></item><item><title>Execute E-Business Suite Security Report</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=394&amp;tn=Execute E-Business Suite Security Report</link><description>This built-in report validates the profile option values, seeded application user accounts for security. &amp;nbsp;Use the following procedure to execute the report:Start Oracle E-Business SuiteConnect to responsibility Application DiagnosticsSelect t ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=394&amp;tn=Execute E-Business Suite Security Report'>View More</a>]]></description></item><item><title>Execute Database Security Report</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=393&amp;tn=Execute Database Security Report</link><description>Start Oracle E-Business SuiteConnect to responsibility Application DiagnosticsSelect the Diagnose menu optionClick button Select Application and select Application &amp;quot;Oracle Application Object Library&amp;quot;Scroll down to group &amp;quot;EbusinessSecurity&amp;quot;Select t ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=393&amp;tn=Execute Database Security Report'>View More</a>]]></description></item><item><title>Change passwords and disable unused default Oracle Applications accounts</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=247&amp;tn=Change passwords and disable unused default Oracle Applications accounts</link><description>Oracle ships seeded user accounts with default passwords. Change the default passwords immediately.Default passwords for database accounts are widely known, and if not changed could allow unauthorized access to various parts of the system.&amp;nbsp;Al ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=247&amp;tn=Change passwords and disable unused default Oracle Applications accounts'>View More</a>]]></description></item><item><title>Enable Detail Auditing for Key Oracle EBS Tables</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=390&amp;tn=Enable Detail Auditing for Key Oracle EBS Tables</link><description>Consider auditing some of the key tables that control system security:ALR_ALERTSFND_AUDIT_COLUMNSFND_AUDIT_GROUPSFND_AUDIT_SCHEMASFND_AUDIT_TABLESFND_CONCURRENT_PROGRAMSFND_DATA_GROUPSFND_DATA_GROUP_UNITSFND_ENABLED_PLSQLFND_FLEX_VALIDATIONFND_FOR ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=390&amp;tn=Enable Detail Auditing for Key Oracle EBS Tables'>View More</a>]]></description></item><item><title>Review Unsuccessful Logins </title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=389&amp;tn=Review Unsuccessful Logins </link><description>The system automatically stores unsuccessful logon attempts in the APPLSYS.FND_UNSUCCESSFUL_LOGINS and ICX.ICX_FAILURES tables. The ICX_FAILURES table holds more information than the FND_UNSUCCESSFUL_LOGINS. Both the FND_UNSUCCESSFUL_LOGINS and IC ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=389&amp;tn=Review Unsuccessful Logins '>View More</a>]]></description></item><item><title>Track last updated details using Who Column Values</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=388&amp;tn=Track last updated details using Who Column Values</link><description>For most E-Business Suite tables, database rows are updated with the creation and last update information. The system stores this information in the following columns (known as &#8220;Who Columns&#8221;):       Who Column Name&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=388&amp;tn=Track last updated details using Who Column Values'>View More</a>]]></description></item><item><title>Review System Audit Reports </title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=387&amp;tn=Review System Audit Reports </link><description>Oracle E-Business Suite ships standard reports to access signon, unsuccessful signon, responsibility usage, form usage and concurrent request usage. Access these reports through the system administrator responsibility. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=387&amp;tn=Review System Audit Reports '>View More</a>]]></description></item><item><title>Enable Privileged User and System Activity With OAM</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=386&amp;tn=Enable Privileged User and System Activity With OAM</link><description>Oracle Application Manager (OAM) provides screens for monitoring current and past system activity. In addition, OAM provides a framework extensible for running custom OAM reports. Monitoring features include current and historic user activity down ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=386&amp;tn=Enable Privileged User and System Activity With OAM'>View More</a>]]></description></item><item><title>Enable Application Server Trust Level Option</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=249&amp;tn=Enable Application Server Trust Level Option</link><description>Responsibilities or applications with the specified level of trust can only be accessed by an application server with at least the same level of trust. Users can see this profile option, but they cannot update it. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=249&amp;tn=Enable Application Server Trust Level Option'>View More</a>]]></description></item><item><title>Limit Access to Forms Allowing SQL Query</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=385&amp;tn=Limit Access to Forms Allowing SQL Query</link><description>To improve flexibility, some forms allow users to enter SQL statements. Unfortunately, this feature may be abused. Restrict access to these forms by assigning the responsibility to a small group of users. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=385&amp;tn=Limit Access to Forms Allowing SQL Query'>View More</a>]]></description></item><item><title>Limit Access to Security Related Forms</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=384&amp;tn=Limit Access to Security Related Forms</link><description>Some forms allow users to modify the EBS security setup. Through these forms users could alter security configuration (e.g. grant inappropriate privileges to themselves or to others). Assign users only those responsibilities necessary for them to  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=384&amp;tn=Limit Access to Security Related Forms'>View More</a>]]></description></item><item><title>Restrict and review administrative responsibilities assigned to users</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=383&amp;tn=Restrict and review administrative responsibilities assigned to users</link><description>Oracle Applications responsibilities like SYSADMIN responsibility has broad administrative privileges. For this reason, regularly review this list of users having administrative responsibilities including SYSADMIN and product administrative respon ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=383&amp;tn=Restrict and review administrative responsibilities assigned to users'>View More</a>]]></description></item><item><title>Activate Secure Server Authentication to Oracle Application Database Server</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=382&amp;tn=Activate Secure Server Authentication to Oracle Application Database Server</link><description>Usually Oracle EBS is deployed in a multi-tier configuration with one database server and many possible middle-tier application servers. The application servers include Apache JSP/Servlet, Forms, Discoverer and also some client programs such as Ap ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=382&amp;tn=Activate Secure Server Authentication to Oracle Application Database Server'>View More</a>]]></description></item><item><title>Configure Concurrent Manager For Safe Authentication</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=381&amp;tn=Configure Concurrent Manager For Safe Authentication</link><description>Concurrent Manager passes the APPS schema password to concurrent programs on the command line. Because some Operating Systems allow all machine users to read a program&#8217;s command line arguments, the password may be intercepted. ENCRYPT signals Conc ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=381&amp;tn=Configure Concurrent Manager For Safe Authentication'>View More</a>]]></description></item><item><title>Minimize usage of shared application accounts</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=380&amp;tn=Minimize usage of shared application accounts</link><description>When users share one generic account associating accountability to individual users is a challenge. System cannot identify which user performs a function. Instead, create shared responsibilities which is assigned to multiple users. It helps to sha ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=380&amp;tn=Minimize usage of shared application accounts'>View More</a>]]></description></item><item><title>Enable Oracle User Management (UMX)</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=248&amp;tn=Enable Oracle User Management (UMX)</link><description>UMX provides a common user registration flow in which a user can enter a new password or select to have one generated randomly. UMX uses workflow to drive the registration process once a request has been submitted. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=248&amp;tn=Enable Oracle User Management (UMX)'>View More</a>]]></description></item><item><title>Enable custom password profile options for Oracle Application Login</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=245&amp;tn=Enable custom password profile options for Oracle Application Login</link><description>Enabling the profile options support strong application passwords, account lockout after failed logon attempts and session inactivity timeout.For additional &amp;nbsp;password security custom password rules can be implemented by using Signon Password  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=245&amp;tn=Enable custom password profile options for Oracle Application Login'>View More</a>]]></description></item><item><title>Use DMZ architecture to manage external/internet implementation</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=377&amp;tn=Use DMZ architecture to manage external/internet implementation</link><description>If Oracle EBS is exposed to the external users using internet, implement DMZ, external web-tiers, firewall and reverse proxies in a secure external EBS deployment ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=377&amp;tn=Use DMZ architecture to manage external/internet implementation'>View More</a>]]></description></item><item><title>Use SSL(HTTPS) between client(browser) and web server</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=376&amp;tn=Use SSL(HTTPS) between client(browser) and web server</link><description>Information sent over the network and across the internet in http protocol is easily intercepted. Secure sockets layer(SSL) is a well known encryption scheme that ensures safe transfer of data in-transit.&amp;nbsp; ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=376&amp;tn=Use SSL(HTTPS) between client(browser) and web server'>View More</a>]]></description></item><item><title>Disable unauthenticated access using workflow notification mailer</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=375&amp;tn=Disable unauthenticated access using workflow notification mailer</link><description>When the parameter SEND_ACCESS_KEY is set to Y in workflow e-mail notification settings, Oracle EBS suite sign-on process is bypassed since the e-mail notification contains an access key. When set to N, an unauthenticated user who clicks on the no ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=375&amp;tn=Disable unauthenticated access using workflow notification mailer'>View More</a>]]></description></item><item><title>Hide  critical application account passwords in log files</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=374&amp;tn=Hide  critical application account passwords in log files</link><description>adpatch utility used for patching Oracle application tier stores passwords in clear text if flags are not properly used during the adpatch execution ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=374&amp;tn=Hide  critical application account passwords in log files'>View More</a>]]></description></item><item><title>Review GUEST application user account responsibility</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=246&amp;tn=Review GUEST application user account responsibility</link><description>Oracle EBS uses GUEST application account to represent unauthenticated user session for certain applications. Limit guest user responsibilities to those necessary for sign-on and guest access. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=246&amp;tn=Review GUEST application user account responsibility'>View More</a>]]></description></item><item><title>Encrypt creditcard and other sensitive information</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=244&amp;tn=Encrypt creditcard and other sensitive information</link><description>Oracle Payables, Oracle Order Capture, Oracle Order Management, Oracle Service Contracts, Oracle istore and iPayments modules in Oracle applications store creditcard information of customers. It is recommended that creditcard encryption is enabled ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=244&amp;tn=Encrypt creditcard and other sensitive information'>View More</a>]]></description></item><item><title>Database(Oracle) Best Practices</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=242&amp;tn=Database(Oracle) Best Practices</link><description>Refer to Oracle Database Best Practices &amp;nbsp;at&amp;nbsp;http://www.checklist20.com/bestpractices.html#cid=70&amp;amp;cn=Oracle%20Database ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=242&amp;tn=Database(Oracle) Best Practices'>View More</a>]]></description></item><item><title>Harden  external web servers </title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=251&amp;tn=Harden  external web servers </link><description>If any of the E-biz modules are implemented for external partners and customers, setup external webtiier with minimal required codebase. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=251&amp;tn=Harden  external web servers '>View More</a>]]></description></item><item><title>Enable Application Auditing for critical resources</title><link>http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=250&amp;tn=Enable Application Auditing for critical resources</link><description>Set SIGNONAUDIT:LEVEL to &amp;quot;Form&amp;quot; at the site level. At this setting, thesystem logs all user sign-ons, responsibility selections and form accesses to APPLSYS.FND_LOGINS, APPLSYS.FND_LOGIN_RESPONSIBILITIES and APPLSYS.FND_LOGIN_RESP_FORMS. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=146&amp;cn=Oracle E-business (General)&amp;tid=250&amp;tn=Enable Application Auditing for critical resources'>View More</a>]]></description></item></channel></rss>
