Index

A  B  C  D  E  F  G  H  I  L  M  N  O  P  R  S  T  U  V  W  

A

  • access control
    • discretionary 1
    • understanding 1
  • access mediation
    • and views 1
    • enforcement options 1
    • introduction 1
    • label evaluation 1
    • program units 1
  • ADD_GROUPS procedure
    • inverse groups 1
  • ALL_CONTROL option 1, 2, 3
  • ALL_SA_AUDIT_OPTIONS view 1
  • ALL_SA_COMPARTMENTS view 1, 3
  • ALL_SA_DATA_LABELS view 1, 3
  • ALL_SA_GROUPS view 1, 3
  • ALL_SA_LABELS view 1
  • ALL_SA_LEVELS view 1
  • ALL_SA_POLICIES view 1
  • ALL_SA_PROG_PRIVS view 1
  • ALL_SA_SCHEMA_POLICIES view 1
  • ALL_SA_TABLE_POLICIES view 1
  • ALL_SA_USER_LABELS view 1
  • ALL_SA_USER_LEVELS view 1
  • ALL_SA_USER_PRIVS view 1
  • ALL_SA_USERS view 1
  • ALTER_GROUP_PARENT
    • inverse groups 1
  • ALTER_GROUPS procedure
    • inverse groups 1
  • ALTER_POLICY procedure
    • inverse groups 1
  • ANALYZE command 1
  • APPLY_SCHEMA_POLICY procedure
    • with inverse groups 1
  • APPLY_TABLE_POLICY procedure
    • with inverse groups 1
  • architecture, Oracle Label Security 1
  • AS SYSDBA clause 1
  • AUDIT_LABEL_ENABLED function 1
  • AUDIT_TRAIL parameter 1
  • auditing
    • audit trails 1, 2, 3
    • creating audit view 1
    • disabling 1
    • dropping audit view 1
    • enabling
      • SA_AUDIT_ADMIN.AUDIT procedure 1
    • finding audit options 1
    • finding if labels are recorded 1
    • Oracle Label Security 1, 2
    • recording policy labels 1
    • SA_AUDIT_ADMIN.AUDIT_LABEL_ENABLED function 1
    • SA_AUDIT_ADMIN.AUDIT_LABEL procedure 1
    • SA_AUDIT_ADMIN.CREATE_VIEW procedure 1
    • SA_AUDIT_ADMIN.DROP_VIEW procedure 1
    • SA_AUDIT_ADMIN.NOAUDIT_LABEL procedure 1
    • SA_AUDIT_ADMIN package 1
    • strategy 1
    • systemwide 1
    • types of 1
    • views 1

B

  • B-tree indexes 1

C

  • CDB_OLS_STATUS data dictionary view 1
  • CDB_OLS_STATUS view 1
  • CDBs
    • Oracle Label Security 1
  • CHAR_TO_LABEL function 1, 2, 3
  • CHECK_CONTROL option
    • and labeling functions 1
    • and label update 1, 2
    • definition 1
    • with other options 1
  • CHECK_WRITE function 1
  • child rows
    • deleting 1
    • inserting 1
    • updating 1
  • Cloud Control login 1
  • COMPACCESS privilege 1
    • inverse groups 1, 2
  • compartments
    • altering 1
    • creating 1
    • definition 1, 2
    • deleting 1
    • example 1, 2
    • finding 1
    • finding compartments user can read in session 1
    • finding compartments user can write to in session 1
    • finding user information 1
    • SA_COMPONENTS.ALTER_COMPARTMENT procedure 1
    • SA_COMPONENTS.CREATE_COMPARTMENT procedure 1
    • SA_COMPONENTS.DROP_COMPARTMENT procedure 1
    • SA_USER_ADMIN.ADD_COMPARTMENTS procedure 1
    • SA_USER_ADMIN.ALTER_COMPARTMENTS 1
    • SA_USER_ADMIN.DROP_COMPARTMENTS procedure 1
    • SA_USER_ADMIN.SET_COMPARTMENTS procedure 1
    • SA_USER_ADMIN package 1
    • setting authorizations 1, 2
    • tutorial on using 1
  • components
    • SA_COMPONENT package 1
    • SA_USER_ADMIN.DROP_ALL_COMPARTMENTS procedure 1
  • CON 1
  • configuration of Oracle Label security
    • finding status 1
    • finding status in multitenant environment 1
  • connection parameters 1
  • CREATE_GROUP procedure
    • inverse groups 1
  • CREATE_POLICY procedure
    • inverse groups 1
  • CREATE FUNCTION statement 1
  • CREATE PACKAGE BODY statement 1
  • CREATE PACKAGE statement 1
  • CREATE PROCEDURE statement 1
  • CREATE TABLE AS SELECT statement 1
  • creating databases 1

D

  • data
    • label-based access 1
  • database links 1
  • databases, creating additional 1
  • data dictionary tables 1, 2, 3, 4
  • data labels
    • checking if label is data label 1
    • finding label and tag information 1
    • SA_UTL.DATA_LABEL function 1
  • Data Pump export
    • row labels 1
  • Data Pump import 1
  • DBA_OLS_STATUS view 1
  • DBA_policyname_AUDIT_TRAIL view 1
  • DBA_SA_AUDIT_OPTIONS view 1
  • DBA_SA_COMPARTMENTS view 1, 2
  • DBA_SA_DATA_LABELS view 1
  • DBA_SA_GROUP_HIERARCHY view 1
  • DBA_SA_GROUPS view 1, 2
  • DBA_SA_LABELS view 1, 2
  • DBA_SA_LEVELS view 1, 2
  • DBA_SA_POLICIES view 1
  • DBA_SA_PROG_PRIVS view 1
  • DBA_SA_SCHEMA_POLICIES view 1, 2
  • DBA_SA_TABLE_POLICIES view 1, 2
  • DBA_SA_USER_COMPARTMENTS view 1
  • DBA_SA_USER_GROUPS view 1
  • DBA_SA_USER_LABELS view 1
  • DBA_SA_USER_LEVELS view 1
  • DBA_SA_USER_PRIVS view 1
  • DBA_SA_USERS view 1
  • default port 1
  • default row label 1
  • DELETE_CONTROL option 1, 2
  • DELETERESTRICT option 1
  • deleting labeled data 1
  • demobld.sql file 1
  • disabling OLS 1
  • disabling Oracle Label Security 1
  • discretionary access control (DAC) 1
  • distributed databases
    • connecting to 1
    • multiple policies 1
    • Oracle Label Security configuration 1
    • remote session label 1
  • dominance
    • definition 1
    • functions
      • about 1
    • greatest lower bound 1
    • inverse groups 1
    • least upper bound 1
    • overview 1
  • DOMINATED_BY function 1
  • DOMINATES function 1
  • dropping for specified compartments 1
  • DROP USER CASCADE restriction 1
  • duties
    • of security administrators 1

E

  • enabling OLS 1
  • enforcement options
    • and UPDATE 1
    • combinations of 1
    • exemptions 1
    • guidelines 1
    • INVERSE_GROUP 1
    • list of 1
    • overview 1
    • viewing 1
  • EXEMPT ACCESS POLICY privilege 1
  • Export utility
    • LBACSYS restriction 1
    • policy enforcement 1
    • row labels 1, 2
  • external tables 1

F

  • FULL privilege 1, 2
  • function call 1, 2

G

  • granularity
    • to data access 1
  • GREATEST_LBOUND function
    • inverse groups 1
  • groups
    • altering 1
    • altering parent groups 1
    • creating group parent 1
    • definition 1, 2
    • deleting 1
    • example 1, 2
    • finding for entire database 1
    • finding hierarchy of parent-child relationships 1
    • finding policy groups 1
    • hierarchical 1, 3, 5, 7
    • inverse 1
    • parent 1, 4, 6, 9
    • read/write access 1
    • SA_COMPONENTS.ALTER_GROUP_PARENT procedure 1
    • SA_COMPONENTS.ALTER_GROUP procedure 1
    • SA_COMPONENTS.CREATE_GROUP procedure 1
    • SA_COMPONENTS.DROP_GROUP 1
    • SA_SESSION.GROUP_READ function 1
    • SA_SESSION.GROUP_WRITE function 1
    • SA_USER_ADMIN.ADD_GROUPS procedure 1
    • SA_USER_ADMIN.ALTER_GROUPS procedure 1
    • SA_USER_ADMIN.DROP_ALL_GROUPS procedure 1
    • SA_USER_ADMIN.DROP_GROUPS procedure 1
    • SA_USER_ADMIN.SET_GROUPS procedure 1
    • SA_USER_ADMIN package 1
    • setting authorizations 1, 2
    • tutorial on using 1

H

  • HIDE 1, 2, 3
  • HIDE option
    • default 1
    • discussion of 1
    • example 1
    • importing hidden column 1
    • inserting data 1
    • not exported 1
    • per-table basis 1
    • PL/SQL restriction 1
    • policy label column
      • inserting data when hidden 1
    • schema level 1

I

  • impdp
    • See: Data Pump import
  • Import utility
    • importing labeled data 1, 2
    • importing policies 1
    • importing unlabeled data 1
    • with Oracle Label Security 1
  • indexes 1
  • INITIAL_LABEL variable 1
  • INITIAL_ROW_LABEL variable 1
  • initialization parameters
    • AUDIT_TRAIL 1
  • INSERT_CONTROL option 1, 2
  • inserting labeled data 1, 2
  • INTO TABLE clause 1
  • INVERSE_GROUP enforcement option
    • behavior of procedures 1
    • implementation 1
  • inverse groups
    • and label components 1
    • COMPACCESS privilege 1, 2
    • computed labels 1
    • dominance 1
    • implementation of 1
    • introduction 1
    • Max Read Groups 1
    • Max Write Groups 1
    • parent-child unsupported 1
    • read algorithm 1
    • session labels 1
    • SET_DEFAULT_LABEL 1
    • SET_LABEL 1
    • SET_ROW_LABEL 1, 2
    • user privileges 1
    • write algorithm 1

L

  • LABEL_DEFAULT option
    • and labeling functions 1, 2
    • authorizing compartments 1
    • authorizing groups 1
    • importing unlabeled data 1
    • inserting labeled data 1
    • with enforcement options 1
    • with SA_SESSION.SET_ROW_LABEL 1
  • LABEL_TO_CHAR function 1, 2, 3
  • LABEL_UPDATE option
    • and labeling functions 1, 2
    • and privileges 1
    • and WRITE_CONTROL 1
    • and WRITEUP 1, 4
    • definition 1
    • evaluation process 1
    • with enforcement options 1
  • label-based security 1
  • label components
    • defining 1
    • in distributed environment 1
    • industry examples 1
    • interrelation 1
  • label evaluation process
    • COMPACCESS read 1
    • COMPACCESS write 1
    • inverse groups, COMPACCESS 1
    • LABEL_UPDATE 1
    • read access 1
    • read access, inverse groups 1
    • write access 1
    • write access, inverse groups 1
  • labeling functions
    • ALL_CONTROL and NO_CONTROL 1
    • and CHECK_CONTROL 1
    • and LABEL_DEFAULT 1, 2
    • and LABEL_DEFAULTlLABEL_DEFAULT option
      • and labeling functions 1
    • and LABEL_UPDATE 1, 2
    • and LBACSYS 1
    • creating 1
    • example 1
    • how they work 1
    • importing unlabeled data 1
    • in force 1
    • inserting data 1
    • introduction 1
    • override manual insert 1
    • specifying 1
    • testing 1
    • UPDATE 1
    • using 1
    • with enforcement options 1
  • label policy containers
    • creating 1
  • labels 1, 2
    • administering 1
    • altering 1
    • and performance 1
    • checking if a data label 1
    • checking if changed 1
    • creating 1
    • data and user 1
    • deleting 1
    • finding greatest lower bound 1
    • finding least upper bound 1
    • finding tags and types of 1
    • merging 1
    • non-comparable 1
    • relationships between 1
    • restoring default for session 1
    • SA_LABEL_ADMIN.ALTER_LABEL procedure 1
    • SA_LABEL_ADMIN.CREATE_LABEL procedure 1
    • SA_LABEL_ADMIN.DROP_LABEL procedure 1
    • SA_LABEL_ADMIN package 1
    • SA_SESSION.LABEL function 1
    • SA_SESSION.MAX_READ_LABEL function 1
    • SA_SESSION.MAX_WRITE_LABEL function 1
    • SA_SESSION.MIN_WRITE_LABEL function 1
    • SA_SESSION.RESTORE_DEFAULT_LABELS 1
    • SA_SESSION.SET_LABEL procedure 1
    • SA_SESSION.SET_ROW_LABEL procedure 1
    • SA_USER_ADMIN.SET_USER_LABELS procedure 1
    • SA_USER_ADMIN package 1
    • SA_UTL.CHECK_LABEL_CHANGE function 1
    • SA_UTL.GREATEST_LBOUND function 1
    • SA_UTL.LEAST_UBOUNDfunction 1
    • SA_UTL.SET_LABEL procedure 1
    • saving default session label 1
    • setting row label 1
    • syntax 1, 2
    • valid 1, 2, 3
    • with inverse groups 1
  • label tags
    • converting from string 1
    • converting to string 1
    • distributed environment 1
    • example 1
    • inserting data 1
    • introduction 1, 2
    • manually defined 1, 2
    • strategy 1
    • using in WHERE clauses 1
  • LBAC_LABEL data type 1
  • LBACSYS
    • export 1
    • import 1
    • login 1
  • LBACSYS default user account
    • about 1
    • best practice guideline 1
  • LBACSYS schema
    • and labeling functions 1
    • creating additional databases 1
    • data dictionary tables 1
    • export restriction 1
  • LEAST_UBOUND function
    • inverse groups 1
  • levels
    • about 1
    • altering levels 1
    • creating 1
    • definition 1, 2
    • deleting 1
    • example 1, 2
    • finding 1
    • SA_COMPONENTS.ALTER_LEVEL procedure 1
    • SA_COMPONENTS.CREATE_LEVEL procedure 1
    • SA_COMPONENTS.DROP_LEVEL procedure 1
    • SA_SESSION.MAX_LEVEL function 1
    • SA_SESSION.MIN_LEVEL function 1
    • SA_USER_ADMIN.SET_LEVELS procedure 1
    • setting authorizations 1, 2
    • tutorial on using 1
  • logging into Oracle Label Security
    • from Cloud Control 1
    • from SQL*Plus 1
  • login
    • Cloud Control 1
    • LBACSYS 1

M

  • materialized views 1, 2
  • Max Read Groups 1
  • Max Write Group 1
  • MERGE_LABEL function 1
  • multitenant container databases
    • See: CDBs

N

  • NO_CONTROL option 1, 2
  • NUMBER data type 1

O

  • object privileges
    • and Oracle Label Security privileges 1
    • and trusted stored program units 1, 2
  • OCI_ATTR_APPCTX_LIST 1
  • OCI_ATTR_APPCTX_SIZE 1
  • OCIAttrSet 1, 2
  • OCI interface 1
  • OCIParamGet 1
  • OLS_DOMINATED_BY function 1
  • OLS_DOMINATES function 1
  • OLS_GLBD function 1
  • OLS_GREATEST_LBOUND function 1
  • OLS_LABEL_DOMINATES function
    • about 1
    • in Database Vault policies 1
    • in Data Redaction policies 1
  • OLS_LEAST_UBOUND function 1
  • OLS_LUBD function 1
  • OLS_STRICTLY_DOMINATED_BY function 1
  • OLS_STRICTLY_DOMINATES function 1
  • olsadmintool commannds
    • addadmin 1
    • addpolcreator 1
    • adduser 1
    • altercompartent 1
    • altergroup 1
    • altergroupparent 1
    • alterlabel 1
    • alterlevel 1
    • alterpolicy 1
    • audit 1
    • createcompartment 1
    • creategroup 1
    • createlabel 1
    • createlevel 1
    • createpolicy 1
    • createprofile 1
    • describeprofile 1
    • dropadmin 1
    • dropcompartment 1
    • dropgroup 1
    • droplabel 1
    • droplevel 1
    • droppolcreator 1
    • droppolicy 1
    • dropprofile 1
    • dropuser 1
    • help 1
    • listprofile 1
    • noaudit 1
  • olsoidsync commannd 1
  • OptionsA 1
  • Oracle Database Vault
    • using OLS_LABEL_DOMINATES function with 1
  • Oracle Data Redaction
    • using OLS_LABEL_DOMINATES function with 1
  • Oracle Enterprise Manager
    • administering labels 1
  • Oracle Internet Directory
    • configuring OLS after switchover to standby database 1
    • integration with OLS 1
    • OID with Oracle Data Guard 1
    • Oracle Label Security
      • about 1
      • administrator duties in 1
      • bootstrapping databases 1
      • configuring, about 1
      • configuring, permission for 1
      • configuring, steps 1
      • integrated capabilities of 1
      • PL/SQL procedures for policy administrators 1
      • policy attributes in 1
      • profiles, about 1
      • provisioning profiles, about 1
      • provisioning profiles, changing database connection information 1
      • provisioning profiles, managing 1
      • restrictions on new data label creation 1
      • security roles and permitted actions 1
      • subscribing policies in 1
      • superseded PL/SQL statements 1
      • synchronizing database with OID 1
      • un-registering database 1
  • Oracle Label Security
    • about 1
    • benefits 1
    • checking if registered and enabled 1
    • DBA_OLS_STATUS data dictionary view 1
    • privileges required to use 1
    • registering 1
  • Oracle Label Security (OLS)
    • integration with Oracle Internet Directory 1
  • Oracle Label Security data dictionary views
    • about 1
    • ALL_SA_AUDIT_OPTIONS 1
    • ALL_SA_COMPARTMENTS 1, 2
    • ALL_SA_DATA_LABELS 1, 2
    • ALL_SA_GROUPS 1, 2
    • ALL_SA_LABELS 1
    • ALL_SA_LEVELS 1, 2
    • ALL_SA_POLICIES 1
    • ALL_SA_PROG_PRIVS 1
    • ALL_SA_SCHEMA_POLICIES 1
    • ALL_SA_TABLE_POLICIES 1
    • ALL_SA_USER_LABELS 1
    • ALL_SA_USER_LEVELS 1
    • ALL_SA_USER_PRIVS 1
    • ALL_SA_USERS 1
    • CDB_OLS_STATUS 1
    • DBA_OLS_STATUS 1
    • DBA_SA_AUDIT_OPTIONS 1
    • DBA_SA_GROUP_HIERARCHY 1
    • DBA_SA_LABELS 1
    • DBA_SA_POLICIES 1
    • DBA_SA_PROG_PRIVS 1
    • DBA_SA_SCHEMA_POLICIES 1
    • DBA_SA_TABLE_POLICIES 1
    • DBA_SA_USER_COMPARTMENTS 1
    • DBA_SA_USER_GROUPS 1
    • DBA_SA_USER_LABELS 1
    • DBA_SA_USER_LEVELS 1
    • DBA_SA_USER_PRIVS 1
    • DBA_SA_USERS 1
    • policies
      • finding information about schema policies 1
    • USER_SA_SESSION 1
  • Oracle Label Security profiles 1
  • ORDER BY clause 1

P

  • packages
    • Oracle Label Security 1
    • SA_AUDIT_ADMIN 1
    • SA_COMPONENTS 1
    • SA_LABEL_ADMIN 1
    • SA_POLICY_ADMIN 1
    • SA_SESSION 1
    • SA_SYSDBA 1
    • SA_USER_ADMIN 1
    • SA_UTL 1
    • trusted stored program units 1
  • partitioning 1, 2
  • PDBs
    • Oracle Label Security 1
  • performance, Oracle Label Security
    • ANALYZE command 1
    • indexes 1
    • label tag strategy 1
    • partitioning 1
    • READ privilege 1
  • PL/SQL
    • recreating labels for import 1
    • SA_UTL package 1, 2
    • trusted stored program units 1
  • pluggable databases
    • See: PDBs
  • policies
    • about creating 1
    • enforcement guidelines 1
    • enforcement options 1, 2, 3, 4, 5
    • finding for current user 1
    • finding for entire database 1
    • finding information about table policies 1
    • finding privileges for program units 1
    • multiple 1, 2
    • OID subscription 1
    • OID unsubscription 1
    • privileges 1, 2
    • SA_POLICY_ADMIN.POLICY_SUBSCRIBE procedure 1
    • SA_POLICY_ADMIN.POLICY_UNSUBSCRIBE procedure 1
    • SA_POLICY_ADMIN package 1
  • policies, schema
    • altering 1
    • applying 1
    • deleting 1
    • disabling 1
    • enabling 1
    • SA_POLICY_ADMIN.ALTER_SCHEMA_POLICY procedure 1
    • SA_POLICY_ADMIN.APPLY_SCHEMA_POLICY procedure 1
    • SA_POLICY_ADMIN.ENABLE_SCHEMA_POLICY policy 1
    • SA_POLICY_ADMIN.REMOVE_SCHEMA_POLICY procedure 1
  • policies, schema, disabling
    • SA_POLICY_ADMIN.DISABLE_SCHEMA_POLICY procedure 1
  • policies, table
    • applying 1
    • deleting 1
    • disabling 1
    • enabling 1
    • SA_POLICY_ADMIN.APPLY_TABLE_POLICY procedure 1
    • SA_POLICY_ADMIN.DISABLE_TABLE_POLICY procedure 1
    • SA_POLICY_ADMIN.ENABLE_TABLE_POLICY procedure 1
    • SA_POLICY_ADMIN.REMOVE_TABLE_POLICY procedure 1
  • policy_DBA role 1, 2, 3
    • about 1
    • auditing policy_DBA role users 1
    • how to use 1
    • required for Data Pump import operations 1
    • required for label management 1
    • required for Oracle Label Security auditing 1
    • required for SA_USER_ADMIN.SET_PROG_PRIVS procedure 1
    • required for SA_USER_ADMIN.SET_USER_PRIVS procedure 1
  • policy label column
    • indexing 1
    • introduction 1, 2
    • retrieving 1
    • retrieving hidden 1
    • storing label tag 1, 2
  • policy label containers
    • about 1
  • policy management
    • altering policies 1
    • creating policies 1
    • deleting policies 1
    • disabling policies 1
    • enabling policies 1
    • SA_SYSDBA.ALTER_POLICY procedure 1
    • SA_SYSDBA.CREATE_POLICY procedure 1
    • SA_SYSDBA.DISABLE_POLICY procedure 1
    • SA_SYSDBA.DROP_POLICY policy 1
    • SA_SYSDBA.ENABLE_POLICY procedure 1
    • SA_SYSDBA package 1
  • predicates
    • access mediation 1
    • errors 1
    • label tag performance strategy 1
    • multiple 1
    • used with policy 1
  • privileges
    • COMPACCESS 1
    • FULL 1, 2
    • Oracle Label Security 1, 2
    • PROFILE_ACCESS 1
    • program units 1
    • READ 1, 2, 3
    • row label 1
    • SA_USER_ADMIN.SET_USER_PRIVS procedure 1
    • trusted stored program units 1
    • WRITEACROSS 1, 2
    • WRITEDOWN 1, 2
    • WRITEUP 1, 2
  • PROFILE_ACCESS privilege 1
  • program units
    • finding policy privileges for 1
  • propagated 1

R

  • RAC 1
  • READ_CONTROL option
    • algorithm 1
    • and CHECK_CONTROL 1
    • and child rows 1
    • definition 1
    • referential integrity 1
    • with other options 1
    • with predicates 1
  • read access
    • algorithm 1, 2
    • introduction 1
  • reading down 1
  • read label 1
  • READ privilege 1, 2, 3
  • re-enabling Oracle Label Security 1
  • referential integrity 1, 2, 3
  • registering Oracle Label Security 1
  • releasability 1
  • remote users 1
  • REPADMIN account 1, 2
  • replication
    • materialized views (snapshots) 1, 2, 3
    • with Oracle Label Security 1, 2
  • replication administrator 1
  • restrictions, Oracle Label Security 1
  • row labels
    • default 1, 2, 3, 4, 5, 6
    • example 1
    • finding current 1
    • in distributed environment 1
    • inserting 1
    • LABEL_DEFAULT option 1, 2
    • privileges 1
    • restoring 1
    • SA_USER_ADMIN.SET_ROW_LABEL procedure 1
    • SA_UTL.NUMERIC_ROW_LABEL function 1
    • SA_UTL.SET_ROW_LABEL procedure 1
    • saving defaults 1
    • setting 1, 2
    • setting compartments 1
    • setting for current database session 1
    • setting for user’s initial use 1
    • setting groups 1
    • setting levels 1
    • understanding 1
    • updating 1
    • viewing 1

S

  • SA_AUDIT_ADMIN
    • procedures, listed 1
  • SA_AUDIT_ADMIN.AUDIT_LABEL_ENABLED procedure 1
  • SA_AUDIT_ADMIN.AUDIT_LABEL procedure 1
  • SA_AUDIT_ADMIN.AUDIT procedure 1
  • SA_AUDIT_ADMIN.CREATE_VIEW procedure 1
  • SA_AUDIT_ADMIN.DROP_VIEW procedure 1
  • SA_AUDIT_ADMIN.NOAUDIT_LABEL procedure 1
  • SA_AUDIT_ADMIN.NOAUDIT procedure 1
  • SA_AUDIT_ADMIN PL/SQL package
    • about 1
  • SA_COMPONENTS
    • procedures, listed 1
  • SA_COMPONENTS.ALTER_COMPARTMENT procedure 1
  • SA_COMPONENTS.ALTER_GROUP_PARENT procedure 1
  • SA_COMPONENTS.ALTER_GROUP procedure 1
  • SA_COMPONENTS.ALTER_LEVEL procedure 1
  • SA_COMPONENTS.CREATE_COMPARTMENT procedure 1
  • SA_COMPONENTS.CREATE_GROUP procedure 1
  • SA_COMPONENTS.CREATE_LEVEL procedure 1
  • SA_COMPONENTS.DROP_COMPARTMENT procedure 1
  • SA_COMPONENTS.DROP_GROUP procedure 1
  • SA_COMPONENTS.DROP_LEVEL procedure 1
  • SA_COMPONENTS package 1
  • SA_COMPONENTS PL/SQL package
    • about 1
  • SA_LABEL_ADMIN
    • procedures, listed 1
  • SA_LABEL_ADMIN.ALTER_LABEL procedure 1
  • SA_LABEL_ADMIN.CREATE_LABEL procedure 1
  • SA_LABEL_ADMIN.DROP_LABEL procedure 1
  • SA_LABEL_ADMIN PL/SQL package
    • about 1
  • SA_POLICY_ADMIN
    • procedures, listed 1
  • SA_POLICY_ADMIN.ALTER_SCHEMA_POLICY procedure 1
  • SA_POLICY_ADMIN.APPLY_SCHEMA_POLICY procedure 1
  • SA_POLICY_ADMIN.APPLY_TABLE_POLICY procedure 1
  • SA_POLICY_ADMIN.DISABLE_SCHEMA_POLICY procedure 1
  • SA_POLICY_ADMIN.DISABLE_TABLE_POLICY procedure 1
  • SA_POLICY_ADMIN.ENABLE_SCHEMA_POLICY procedure 1
  • SA_POLICY_ADMIN.ENABLE_TABLE_POLICY procedure 1
  • SA_POLICY_ADMIN.POLICY_SUBSCRIBE procedure 1
  • SA_POLICY_ADMIN.POLICY_UNSUBSCRIBE procedure 1
  • SA_POLICY_ADMIN.REMOVE_SCHEMA_POLICY procedure 1
  • SA_POLICY_ADMIN.REMOVE_TABLE_POLICY procedure 1
  • SA_POLICY_ADMIN PL/SQL package
    • about 1
  • SA_SESSION
    • procedures and functions, listed 1
  • SA_SESSION.COMP_READ function 1
  • SA_SESSION.COMP_WRITE function 1
  • SA_SESSION.GROUP_READ function 1
  • SA_SESSION.GROUP_WRITE function 1
  • SA_SESSION.LABEL function 1
  • SA_SESSION.MAX_LEVEL function 1
  • SA_SESSION.MAX_READ_LABEL function 1
  • SA_SESSION.MAX_WRITE_LABEL function 1
  • SA_SESSION.MIN_LEVEL function 1
  • SA_SESSION.MIN_WRITE_LABEL function 1
  • SA_SESSION.PRIVS function 1
  • SA_SESSION.RESTORE_DEFAULT_LABELS procedure 1
  • SA_SESSION.ROW_LABEL function 1
  • SA_SESSION.SA_USER_NAME function 1
  • SA_SESSION.SAVE_DEFAULT_LABELS procedure 1
  • SA_SESSION.SET_ACCESS_PROFILE procedure 1, 2
  • SA_SESSION.SET_LABEL procedure 1
    • and SA_SESSION.RESTORE_DEFAULT_LABELS 1
  • SA_SESSION.SET_ROW_LABEL procedure 1
  • SA_SESSION PL/SQL package
    • about 1
  • SA_SYSDBA
    • procedures, listed 1
  • SA_SYSDBA.ALTER_POLICY procedure 1
  • SA_SYSDBA.CREATE_POLICY procedure 1
  • SA_SYSDBA.DISABLE_POLICY procedure 1
  • SA_SYSDBA.DROP_POLICY procedure 1
  • SA_SYSDBA.ENABLE_POLICY procedure 1
  • SA_SYSDBA PL/SQL package
    • about 1
  • SA_USER_ADMIN.ADD_COMPARTMENTS procedure 1
  • SA_USER_ADMIN.ADD_GROUPS procedure 1
  • SA_USER_ADMIN.ALTER_COMPARTMENTS procedure 1
  • SA_USER_ADMIN.ALTER_GROUPS procedure 1
  • SA_USER_ADMIN.DROP_ALL_COMPARTMENTS procedure 1
  • SA_USER_ADMIN.DROP_ALL_GROUPS procedure 1
  • SA_USER_ADMIN.DROP_COMPARTMENTS procedure 1
  • SA_USER_ADMIN.DROP_GROUPS procedure 1
  • SA_USER_ADMIN.DROP_USER_ACCESS procedure 1
  • SA_USER_ADMIN.SET_COMPARTMENTS procedure 1
  • SA_USER_ADMIN.SET_DEFAULT_LABEL procedure 1
  • SA_USER_ADMIN.SET_GROUPS procedure 1
  • SA_USER_ADMIN.SET_LEVELS procedure 1
  • SA_USER_ADMIN.SET_ROW_LABEL procedure 1
  • SA_USER_ADMIN.SET_USER_LABELS procedure 1
  • SA_USER_ADMIN.SET_USER_PRIVS procedure 1
  • SA_USER_ADMIN package
    • administering stored program units 1
    • overview 1
    • procedures, listed 1
  • SA_USER_ADMIN PL/SQL package
    • about 1
  • SA_UTL.CHECK_LABEL_CHANGE function 1
  • SA_UTL.CHECK_READ function 1
  • SA_UTL.CHECK_WRITE function 1
  • SA_UTL.DATA_LABEL function 1
  • SA_UTL.GREATEST_LBOUND function 1
  • SA_UTL.LEAST_UBOUND function 1
  • SA_UTL.NUMERIC_LABEL function 1
  • SA_UTL.NUMERIC_ROW_LABEL function 1
  • SA_UTL.SET_LABEL procedure 1
  • SA_UTL.SET_ROW_LABEL procedure 1
  • SA_UTL package
    • dominance functions 1
    • overview 1
    • procedures and functions, listed 1
  • SA_UTL PL/SQL package
    • about 1
  • schemas
    • applying policies to 1, 2
    • default policy options 1
    • restrictions on shared 1
  • session labels
    • changing 1
    • computed 1
    • distributed database 1
    • example 1
    • finding 1
    • OCI interface 1
    • restoring to default 1
    • SA_UTL.SET_LABEL 1
    • saving defaults 1
    • setting compartments 1
    • setting groups 1
    • setting user initial 1
    • understanding 1
  • sessions
    • compartments readable by user 1
    • compartments writeable by user 1
    • finding current OLS user 1
    • finding row label 1
    • finding security attributes for 1
    • finding session label number 1
    • finding session privileges 1
    • SA_SESSION.COMP_READ function 1
    • SA_SESSION.COMP_WRITE function 1
    • SA_SESSION.GROUP_READ function 1
    • SA_SESSION.GROUP_WRITE function 1
    • SA_SESSION.LABEL function 1
    • SA_SESSION.MAX_LEVEL function 1
    • SA_SESSION.MAX_READ_LABEL function 1
    • SA_SESSION.MAX_WRITE_LABEL function 1
    • SA_SESSION.MIN_LEVEL function 1
    • SA_SESSION.MIN_WRITE_LABEL function 1
    • SA_SESSION.PRIVS 1
    • SA_SESSION.RESTORE_DEFAULT_LABELS procedure 1
    • SA_SESSION.ROW_LABEL function 1
    • SA_SESSION.SA_USER_NAME function 1
    • SA_SESSION.SAVE_DEFAULT_LABELS procedure 1
    • SA_SESSION.SET_ACCESS_PROFILE procedure 1
    • SA_SESSION.SET_LABEL procedure 1
    • SA_SESSION package 1
    • SA_USER_ADMIN.SET_COMPARTMENTS procedure 1
    • SA_USER_ADMIN.SET_DEFAULT_LABEL procedure 1
    • SA_USER_ADMIN.SET_LEVELS procedure 1
    • SA_UTL.SET_LABEL procedure 1
    • SA_UTL.SET_ROW_LABEL procedure 1
    • saving default session label 1
    • setting label for 1
    • setting OLS privileges for user 1
    • setting row label for 1
  • SET_ACCESS_PROFILE procedure 1
  • SET_DEFAULT_LABEL procedure
    • inverse groups 1, 2
  • SET_GROUPS procedure
    • inverse groups 1
  • SET_LABEL procedure
    • definition 1
    • inverse groups 1, 2
    • on remote database 1
  • SET_PROG_PRIVS function 1
  • SET_ROW_LABEL procedure 1, 2
    • inverse groups 1, 2, 3, 4
  • SET_USER_LABELS procedure
    • inverse groups 1
  • setting label for database session 1
  • shared schema restrictions 1
  • SQL*Loader 1
  • STRICTLY_DOMINATED_BY function 1
  • STRICTLY_DOMINATES function 1
  • SYS_CONTEXT
    • and labeling functions 1
    • variables 1
  • SYS account
    • policy enforcement 1
  • SYSDBA privilege 1
  • system privileges 1, 2, 3

T

  • table rows
    • checking if user can read 1
    • checking if user can write to 1
    • SA_UTL.CHECK_READ function 1
    • SA_UTL.CHECK_WRITE function 1
  • TO_DATA_LABEL function 1, 2
  • TO_LBAC_DATA_LABEL function 1
  • TO_LBAC_DATA_LABEL function, example of using 1
  • triggers 1
  • trusted program units
    • about 1
  • trusted stored program units
    • creating 1
    • error handling 1
    • example 1
    • executing 1
    • introduction 1
    • privileges 1, 2
    • re-compiling 1
    • replacing 1
  • tutorials
    • creating Oracle Label Security compartments 1
    • creating Oracle Label Security groups 1
    • creating Oracle Label Security levels 1

U

  • unified audit trail 1
  • UPDATE_CONTROL option 1, 2
  • updating labeled data 1
  • USER_SA_SESSION view 1
  • user authorizations 1
    • adding for compartments 1
    • adding for groups 1
    • altering for compartments 1
    • altering for groups 1
    • compartments 1, 2
    • dropping for all compartments 1
    • dropping for all groups 1
    • dropping for specified groups 1
    • groups 1, 2
    • levels 1, 2
    • removing all OLS privileges from user 1
    • row labels
      • default 1
    • SA_USER_ADMIN.SET_USER_PRIVS procedure 1
    • understanding 1, 2
  • users
    • finding label-specific information of 1
    • finding level-specific information of 1
    • finding policy-specific privileges of 1
    • finding privileges of OLS users 1
    • LBACSYS default user account 1
  • utilities
    • SA_UTL package 1

V

  • views
    • access mediation 1
    • ALL_SA_AUDIT_OPTIONS 1
    • ALL_SA_COMPARTMENTS 1
    • ALL_SA_GROUPS 1
    • ALL_SA_LABELS 1, 2
    • ALL_SA_LEVELS 1
    • ALL_SA_POLICIES 1
    • ALL_SA_PROG_PRIVS 1
    • ALL_SA_SCHEMA_POLICIES 1
    • ALL_SA_TABLE_POLICIES 1
    • ALL_SA_USER_LABELS 1
    • ALL_SA_USER_LEVELS 1
    • ALL_SA_USER_PRIVS 1
    • ALL_SA_USERS 1
    • CDB_OLS_STATUS 1
    • DBA_OLS_STATUS 1
    • DBA_SA_AUDIT_OPTIONS 1
    • DBA_SA_COMPARTMENTS 1
    • DBA_SA_DATA_LABELS 1
    • DBA_SA_GROUP_HIERARCHY 1
    • DBA_SA_GROUPS 1
    • DBA_SA_LABELS 1
    • DBA_SA_LEVELS 1
    • DBA_SA_POLICIES 1
    • DBA_SA_PROG_PRIVS 1
    • DBA_SA_SCHEMA_POLICIES 1, 2
    • DBA_SA_TABLE_POLICIES 1, 2
    • DBA_SA_USER_COMPARTMENTS 1
    • DBA_SA_USER_GROUPS 1
    • DBA_SA_USER_LABELS 1
    • DBA_SA_USER_LEVELS 1
    • DBA_SA_USER_PRIVS 1
    • DBA_SA_USERS 1

W

  • WRITE_CONTROL option
    • algorithm 1
    • definition 1
    • introduction 1
    • LABEL_UPDATE 1
    • with INSERT, UPDATE, DELETE 1
    • with other options 1
  • write access
    • algorithm 1, 2
    • introduction 1
  • WRITEACROSS privilege 1, 2, 3, 4
  • WRITEDOWN privilege 1, 2, 3, 4
  • write label 1
  • WRITEUP privilege 1, 2