Security

All access to customer systems is managed by our Remote Access Infrastructure (RAI).  Remote DBAs must often quickly move from one customer network to another.  If such quick-shifting access is not designed deliberately, such as lazily connecting to multiple customers simultaneously from a laptop – there is a danger that the remote DBA might unwittingly allow traffic from one customer network to become visible on another customer network, or worse, bridge the two networks together.

Our RAI isolates remote network access between customers ensuring traffic from one customer is never visible on another customers network, while allowing our DBAs to safely shift from customer to customer as required.  All DBAs must authenticate individually to the RAI, and must be specifically authorized to access a customer system.  We can report on Blue Gecko access levels at any time to assist with regulatory requirements such as PCI, SOX, and HIPPA.

Blue Gecko relies on an encrypted, IPsec VPN tunnel for all remote connections whenever possible.  For customers that do not have a VPN infrastructure, Blue Gecko will provide and manage a Cisco VPN device at no additional charge.  If our customers’ security requirements dictate the use of a specific remote connection method, we will always accommodate such a need.

Customer passwords also receive very special attention:  Often shared passwords (such as the Oracle password) must be shared with Blue Gecko administrators.  We encrypt all shared passwords in a secured database, and Only Blue Gecko administrators who are specifically authorized to view a specific shared password are granted permission to see and use the password.  Access to Pepper is strictly maintained, regularly audited, and customers may receive a report at any time that shows who has access to their passwords.

Related posts from the blog:

  1. Database security in the cloud
    Here’s a great article on database security in the cloud published in eWeek by Slavik Markovich, founder of...
  2. ORA-04031 and ASMM
    Oracle E-Business Suite customer was reporting ORA-04031 errors being returned by the database. There were a number of...
  3. 6 things to do after an Oracle Apps R12 install
    OK, so there are a ton of things to do right after a fresh R12 install.  And before...
  4. Exploring Oracle 11g Tablespace Encryption
    Tablespace encryption encrypts data at the datafile level to keep people from being able to peek at the...
  5. Specificity + Inaccuracy = Yikes!
    Every once in a while I run into a customer with a very specific request:  Please do “this”...