Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Usenet -> c.d.o.misc -> Re: Tough question for oracle DBAs/Solaris Admins. Log shipping.

Re: Tough question for oracle DBAs/Solaris Admins. Log shipping.

From: Stefaan A Eeckels <hoendech_at_ecc.lu>
Date: Sat, 2 Sep 2006 13:25:44 +0200
Message-ID: <20060902132544.9982b41b.hoendech@ecc.lu>


On Sat, 02 Sep 2006 00:35:13 GMT
Ningi <ningi_at_EGGSANDSPAMblueyonder.co.uk> wrote:

> Frank Cusack wrote:
> <snip>
>
> m UNTRUSTED employees, not eliminating trust from the system.
> >
> > No auditor will balk at not having immutable files as long as only
> > trusted employees are in the position to undetectably alter data.
>
> Yes they will. You stand no chance of meeting SEC 17a-4 if ANYBODY
> can alter the data.

Then SEC 17a-4 cannot be met, unless the data is placed on a write-once medium and said medium is stored in an inviolable location (or has such characteristics that it cannot be substituted).

But wait - how do you(*) know that the program that writes the data to the write-once medium doesn't alter it whilst writing?

As usual, the law is an ass.

(*) you = an auditor who cannot read program source code and compile it himself, and execute on a system he has built from the ground up so that he knows it's trusted. And even if the auditor could do all this, why trust the auditor?

-- 
Stefaan A Eeckels
-- 
You rarely have time for everything you want in this life, so you
have to make choices.  And hopefully your choices can come from a
deep sense of who you are.                         -- Fred Rogers
Received on Sat Sep 02 2006 - 06:25:44 CDT

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US