
Planning Security for an Administrative Domain
Managing Security for Backup Networks
6-3
■
Onlookers
These users do not fall into any of the preceding categories of principals, but can
access a larger network that contains the Oracle Secure Backup domain. Onlookers
might own a host outside the domain.
The relationships between assets and principals partially determine the level of
security in the Oracle Secure Backup administrative domain:
■
In the highest level of security, the only principal with access to an asset is the
owner. For example, only the owner of a
client
host can read or modify data from
this host.
■
In a medium level of security, the asset owner and the administrator of the domain
both have access to the asset.
■
In the lowest level of security, any principal can access any asset in the domain.
Identifying Your Backup Environment Type
After you have identified the assets and principals involved in your
administrative
domain
, you can characterize the type of environment in which you are deploying the
domain. The type of environment partially determines which security model to use.
The following criteria partially distinguish types of network environments:
■
Scale
The number of assets and principals associated with a domain plays an important
role in domain security. A network that includes 1000 hosts and 2000 users has
more points of entry for an attacker than a network of 5 hosts and 2 users.
■
Sensitivity of data
The sensitivity of data is measured by how dangerous it would be for the data to
be accessed by a malicious user. For example, the home directory on a
rank-and-file corporate employee's host is presumably less sensitive than a credit
card company's subscriber data.
■
Isolation of communication medium
The security of a network is contingent on the accessibility of network
communications among hosts and devices in the domain. A private, corporate
data center is more isolated in this sense than an entire corporate network.
The following sections describe types of network environments in which Oracle
Secure Backup administrative domains are typically deployed. The sections also
describe the security model typical for each environment.
Single System
The most basic
administrative domain
is illustrated in
Figure 6–1
. It consists of an
administrative server
,
media server
, and
client
on a single host.
Содержание Secure Backup 10.3
Страница 8: ...viii ...
Страница 26: ...About Upgrade Installations 1 16 Oracle Secure Backup Installation and Configuration Guide ...
Страница 82: ...Using obtool 4 14 Oracle Secure Backup Installation and Configuration Guide ...
Страница 110: ...Verifying and Configuring Added Tape Devices 5 28 Oracle Secure Backup Installation and Configuration Guide ...
Страница 152: ...Installation and Configuration D 6 Oracle Secure Backup Installation and Configuration Guide ...