Qortora · Search · Indexed page

docs.oracle.comFetched 2026-08-14T03:13:32Z

Configure Compliance Management

Configure Compliance Management Previous Next JavaScript must be enabled to correctly display this content Configure Compliance Management Before you can use the compliance features, compliance frameworks, compliance standards, and compliance standard rules must be defined for yo…

Open original source · Full cached text

Configure Compliance Management Previous Next JavaScript must be enabled to correctly display this content Configure Compliance Management Before you can use the compliance features, compliance frameworks, compliance standards, and compliance standard rules must be defined for your enterprise. The following sections describe how to define and maintain these compliance entities. About Compliance Frameworks Operations on Compliance Frameworks About Compliance Standards Operations on Compliance Standards About Compliance Standard Rule Folders About Compliance Standard Rules Operations on Compliance Standards Rules About Compliance Frameworks A compliance framework is a hierarchical structure where any node can be mapped to one or more compliance standards, compliance standard rule folders, and compliance standard rules. Compliance frameworks provide a way to map your standards to a structure similar to the regulatory or standards-based compliance structure you use in your company. Managing Compliance Frameworks To manage compliance frameworks, follow these steps: From the Enterprise menu, select Compliance, then Dashboard, then select Library. Click Compliance Frameworks tab. Highlight the compliance framework you want to manage and choose the action you want to perform. Frameworks Provided by Oracle and User-Defined Compliance Frameworks There are compliance frameworks provided by Oracle and user-defined compliance frameworks. Compliance frameworks provided by Oracle include Oracle Support Compliance is a collection of controls that check for expected environment compliance for Oracle Supportability. Oracle Generic Compliance Framework is a standard set of compliance standards and associated controls for tracking changes and events taking place across your IT infrastructure for determining how well your organization is in compliance with your IT policies. Security Technical Implementation Guide (STIG) is a set of standards to ensure Security Technical Implementation Guide (STIG) compliance. User-defined compliance frameworks You can define a compliance framework to satisfy the needs of your organization. Compliance frameworks provided by Oracle cannot be deleted or edited. However, if you want to extend these frameworks, use the Create Like functionality to create your own user-defined frameworks based on the Oracle provided frameworks and then edit the new frameworks. Recommendation: It is highly recommended that you create a top level compliance framework like the ones provided for STIG and Oracle Generic compliance. Benefits of Using Compliance Frameworks Compliance standards are defined to perform tests on targets. Examples include: testing if a configuration value is set properly, test to see if file changes are occurring, and so on. A compliance framework is a way to map how different control areas of your compliance initiative are going to be affected by the results of those tests. An organization may choose to define a compliance framework that extends an Oracle provided compliance framework. This is accomplished by creating a new compliance framework like the Oracle provided compliance framework and include new or existing compliance standards. Then each compliance standard is mapped to an appropriate framework hierarchy folder so that any violation against the standard is also mapped to that framework folder. Each folder in the framework represents one control area. Reasons for Using Compliance Frameworks There are a number of reasons for creating compliance frameworks including: Mapping underlying IT violations to the regulatory and standard compliance controls used by your company so you can easily identify the compliance control areas that will be affected by the violations Compliance auditing at compliance specification level Auditing, security evaluation, and trend analysis What Compliance Frameworks Can Do A compliance framework can: Represent industry-standard compliance control areas or can be created to match your internal frameworks in use. Many companies may start by using an industry-standard framework, but modify it according to their own needs and auditing requirements. Help in IT audits by identifying which compliance controls are at risk and may need compensating controls based on the violations. Without mapping your compliance checks to the control areas affected, it is hard to identify what the real impact would be in a compliance audit. Since compliance frameworks can contain compliance standards of different types (Repository and monitoring), they provide a good way of grouping similar checks of different types for reporting purposes. Usage Note Evaluation Results for a repository rule may become invalidated if a compliance standard rule within a compliance framework is modified or deleted. Evaluation of a compliance standard always references the current compliance standard rule definition for each compliance standard rule within the compliance standard. Operations on Compliance Frameworks You can perform the following operations on a compliance framework: Creating a Compliance Framework Creating Like a Compliance Framework Editing a Compliance Framework Deleting a Compliance Framework Exporting a Compliance Framework Importing a Compliance Framework Browsing Compliance Frameworks Searching Compliance Frameworks The following sections explain these operations. Note: Before you perform any of the operations on compliance frameworks, ensure you have necessary privileges. For example, when creating a compliance framework, ensure you have access to the compliance standards you will be including during the definition of the framework. See Roles and Privileges Needed for Compliance Features. Creating a Compliance Framework To make the creation for the compliance framework easier, ensure that the compliance standards, which will be referred to by the compliance framework, are already defined in the Cloud Control. You can add system out-of-the-box and user-defined compliance standards to any hierarchical element of the compliance framework. If you do not define the compliance standards before hand, you must add them later. To create a compliance framework, follow these steps: From the Enterprise menu, select Compliance, then select Library. Click the Compliance Frameworks tab. Click Create button. Provide the Name and Author and click OK. Once you have provided the information on the definition page, look at the options available when you right-click the name of the compliance framework (located at the top-left of the page). From this list you can create subgroups, include compliance standards, and so on. Click Save. Usage Notes Lifecycle status can be either Development or Production. Development Indicates a compliance framework is under development and that work on its definition is still in progress. While in development mode, all management capabilities of compliance frameworks are supported including editing of the compliance framework and deleting the compliance framework. Results of development compliance standards will NOT be viewable in target and console home pages, and the compliance dashboard. Lifecycle status default is Development. It can be promoted to Production only once. It cannot be changed from Production to Development. Production Indicates a compliance framework has been approved and is of production quality. When a compliance framework is in production mode, its results are rolled up into a compliance dashboard, target and console home page. Production compliance frameworks can only refer to Production compliance standards. A production compliance framework can be edited to add/delete references to production compliance standards only. Lifecycle status cannot be changed from Production to Development. All compliance frameworks with the same keyword will be grouped together when sorted by the Keyword column. If you modify a repository that has been added to a compliance framework, either by editing the compliance standard directly, or by using Import to overwrite the compliance standard with new settings, the existing evaluations become invalid. That is, if this modified compliance standard was included in a compliance framework that was previously evaluated, and has evaluation results, these results are no longer viewable. Adding a Compliance Standard to a Compliance Framework Click on a framework folder element that you want to map a compliance standard to. Right click and select Add Standards to bring up a popup to allow you to select the standards to map to this folder. Use the search criteria to minimize the number of compliance standards that display in the select list. Once you make your selections, click OK. The framework hierarchy screen refreshes and shows your newly included compliance standards under the framework folder element. Editing Importance After you map the compliance standards that are to be part of the selected compliance framework folder, you can edit the importance of each compliance standard for this specific folder. The importance impacts the way the compliance score is calculated for this compliance standard in this framework folder. See Overview of Compliance Score and Importance for details on how this score is computed. Creating Like a Compliance Framework To create a compliance framework like another compliance framework, follow these steps: From the Enterprise menu, select Compliance, then select Library. Click the Compliance Frameworks tab. On the Compliance Framework Library page, highlight the compliance framework you want to use as the base and click the Create Like button. Customize the fields as needed. Ensure that the Compliance Framework name is different from the original compliance framework and any other existing compliance frameworks. Click Save. You can then edit this newly created framework and add or remove standards, subfolders, or modify importance levels. Editing a Compliance Framework Use the edit compliance framework feature to add new compliance standard rules to a compliance framework, or edit details of existing compliance frameworks, or remove compliance standards from the compliance framework. To edit a compliance framework, follow these steps: From the Enterprise menu, select Compliance, then select Library. Click the Compliance Frameworks tab. Highlight the compliance framework you want to edit and click the Edit button. Update the properties as needed. To add standards and subgroups, right-click the name of the framework located at the top left of the page. Click Save. Usage Notes Changing a compliance framework definition may impact trend analysis. The compliance standards you add to a compliance framework may be system-defined and user-defined compliance standards as displayed on the Compliance Standard Library page. If you modify a repository that has been added to a compliance framework, either by editing the compliance standard directly, or by using Import to overwrite the compliance standard with new settings, the existing evaluations become invalid. That is, if this modified compliance standard was included in a compliance framework that was previously evaluated, and has evaluation results, these results are no longer viewable. The compliance framework evaluation results will again become visible after the next evaluation happens. The new evaluation includes the changes to the compliance standard within the compliance framework. The importance impacts the way the compliance score is calculated for this compliance standard in this framework folder. A compliance standard can be added to more than one compliance framework, and can have a different importance when added to a different compliance framework. For example, you could have a compliance standard called Check Password Expired which flags user accounts with expired passwords. This compliance standard may be a member of two compliance frameworks: All System Passwords Secure and 30-day Password Validation. Th…