Oracle Audit Vault Review

The PL/SQL auditing feature helps to control code updates. In data-sensitive environments, leveraging the inbuilt compliance reports can be valuable.


What is most valuable?

The most valuable features of this product are:

  • PL/SQL auditing: It helps to control the code updates in a sensitive environment.

  • Inbuilt compliance reports - In data-sensitive environments where auditing teams require generation of reports for specific database such as SOX-compliant financial databases, HIPAA-compliant healthcare databases or PCI-compliant databases, leveraging these inbuilt reports in Oracle Audit Vault 12c can be of great value.

How has it helped my organization?

We are the implementers of the product to our clients.

What needs improvement?

This product should improve capturing more auditing information for database sessions that connect via applications and also through database links. When the database sessions are generated from the applications that use database links from other databases, by nature the target database won't capture relevant information of the remote sessions. Also in the audit trails, it is of utmost importance who are the data consumers so as to track and control the appropriate use of the information.

There is need to improve capturing of more auditing information for OS logins as well.

For how long have I used the solution?

I have used this solution for three years.

What do I think about the stability of the solution?

I have not encountered any stability issues.

What do I think about the scalability of the solution?

I have not encountered any scalability issues.

How are customer service and technical support?

I would give the technical support a 7/10, i.e., an above-average rating.

Which solution did I use previously and why did I switch?

We have not used any other solution.

How was the initial setup?

The setup for Audit Vault is relatively simple.

However, configuring personalized reports is a nasty task. There are many variables involved and the documentation is not very good. The way the reports can be personalized must be more visual and requires a drag-and-drop feature rather than creating it in a rudimentary manner.

What's my experience with pricing, setup cost, and licensing?

It is an expensive solution. For those customers who do not have any ULA agreements with Oracle, the solution is practically impossible to acquire.

Which other solutions did I evaluate?

We did not evaluate other options.

What other advice do I have?

Those who have already acquired the product, the implementation and use of the product is dependent on its daily use so as to get acquainted with all the features. If they have installed the platform and don't use it regularly, it’s a waste of time and energy.

One day when somebody asks about the audit reports, the database auditors will be in a big problem if they don't know how to generate the requested reports.

Disclosure: My company has a business relationship with this vendor other than being a customer: We are Oracle GOLD Partners.
Add a Comment
Guest
Sign Up with Email