Index

A  B  C  D  E  F  G  H  I  L  M  N  O  P  R  S  T  U  V  W  

A

  • access control
    • discretionary [1]
    • understanding [1]
  • access mediation
    • and views [1]
    • enforcement options [1]
    • introduction [1]
    • label evaluation [1]
    • program units [1]
  • ADD_GROUPS procedure
    • inverse groups [1]
  • ALL_CONTROL option [1] , [2] , [3]
  • ALL_SA_AUDIT_OPTIONS view [1]
  • ALL_SA_COMPARTMENTS view [1]
  • ALL_SA_DATA_LABELS view [1] , [3]
  • ALL_SA_GROUPS view [1] , [3]
  • ALL_SA_LABELS view [1] , [3]
  • ALL_SA_LEVELS view [1] , [3]
  • ALL_SA_POLICIES view [1]
  • ALL_SA_PROG_PRIVS view [1]
  • ALL_SA_SCHEMA_POLICIES view [1]
  • ALL_SA_TABLE_POLICIES view [1]
  • ALL_SA_USER_LABELS view [1]
  • ALL_SA_USER_LEVELS view [1]
  • ALL_SA_USER_PRIVS view [1]
  • ALL_SA_USERS view [1]
  • ALTER_GROUP_PARENT
    • inverse groups [1]
  • ALTER_GROUPS procedure
    • inverse groups [1]
  • ALTER_POLICY procedure
    • inverse groups [1]
  • ANALYZE command [1]
  • APPLY_SCHEMA_POLICY procedure
    • with inverse groups [1]
  • APPLY_TABLE_POLICY procedure
    • with inverse groups [1]
  • architecture, Oracle Label Security [1]
  • AS SYSDBA clause [1]
  • AUDIT_LABEL_ENABLED function [1]
  • AUDIT_TRAIL parameter [1]
  • auditing
    • audit trails [1] , [2] , [3]
    • creating audit view [1]
    • disabling [1]
    • dropping audit view [1]
    • enabling
      • SA_AUDIT_ADMIN.AUDIT procedure [1]
    • finding audit options [1]
    • finding if labels are recorded [1]
    • Oracle Label Security [1] , [2]
    • recording policy labels [1]
    • SA_AUDIT_ADMIN.AUDIT_LABEL_ENABLED function [1]
    • SA_AUDIT_ADMIN.AUDIT_LABEL procedure [1]
    • SA_AUDIT_ADMIN.CREATE_VIEW procedure [1]
    • SA_AUDIT_ADMIN.DROP_VIEW procedure [1]
    • SA_AUDIT_ADMIN.NOAUDIT_LABEL procedure [1]
    • SA_AUDIT_ADMIN package [1]
    • strategy [1]
    • systemwide [1]
    • types of [1]
    • views [1]

B

  • B-tree indexes [1]

C

  • CDBs
    • Oracle Label Security [1]
  • CHAR_TO_LABEL function [1] , [2]
  • CHECK_CONTROL option
    • and labeling functions [1]
    • and label update [1] , [2]
    • definition [1]
    • with other options [1]
  • CHECK_WRITE function [1]
  • child rows
  • Cloud Control login [1]
  • COMPACCESS privilege
  • compartments
    • altering [1]
    • creating [1]
    • definition [1] , [2]
    • deleting [1]
    • example [1] , [2]
    • finding [1]
    • finding compartments user can read in session [1]
    • finding compartments user can write to in session [1]
    • finding user information [1]
    • SA_COMPONENTS.ALTER_COMPARTMENT procedure [1]
    • SA_COMPONENTS.CREATE_COMPARTMENT procedure [1]
    • SA_COMPONENTS.DROP_COMPARTMENT procedure [1]
    • SA_USER_ADMIN.ADD_COMPARTMENTS procedure [1]
    • SA_USER_ADMIN.ALTER_COMPARTMENTS [1]
    • SA_USER_ADMIN.DROP_COMPARTMENTS procedure [1]
    • SA_USER_ADMIN.SET_COMPARTMENTS procedure [1]
    • SA_USER_ADMIN package [1]
    • setting authorizations [1] , [2]
  • components
    • SA_COMPONENT package [1]
    • SA_USER_ADMIN.DROP_ALL_COMPARTMENTS procedure [1]
  • CON [1]
  • configuration of Oracle Label security
    • finding status [1]
  • connection parameters [1]
  • CREATE_GROUP procedure
    • inverse groups [1]
  • CREATE_POLICY procedure
    • inverse groups [1]
  • CREATE FUNCTION statement [1]
  • CREATE PACKAGE BODY statement [1]
  • CREATE PACKAGE statement [1]
  • CREATE PROCEDURE statement [1]
  • CREATE TABLE AS SELECT statement [1]
  • creating databases [1]

D

  • data
    • label-based access [1]
  • database links [1]
  • databases, creating additional [1]
  • data dictionary tables [1] , [2] , [3] , [4]
  • data labels
    • checking if label is data label [1]
    • finding label and tag information [1]
    • SA_UTL.DATA_LABEL function [1]
  • Data Pump export
    • row labels [1]
  • Data Pump import [1]
  • DBA_OLS_STATUS view [1]
  • DBA_policyname_AUDIT_TRAIL view [1]
  • DBA_SA_AUDIT_OPTIONS view [1]
  • DBA_SA_COMPARTMENTS view [1] , [2]
  • DBA_SA_DATA_LABELS view [1]
  • DBA_SA_GROUP_HIERARCHY view [1]
  • DBA_SA_GROUPS view [1] , [2]
  • DBA_SA_LABELS view [1] , [2]
  • DBA_SA_LEVELS view [1] , [2]
  • DBA_SA_POLICIES view [1]
  • DBA_SA_PROG_PRIVS view [1]
  • DBA_SA_SCHEMA_POLICIES view [1] , [2]
  • DBA_SA_TABLE_POLICIES view [1] , [2]
  • DBA_SA_USER_COMPARTMENTS view [1]
  • DBA_SA_USER_GROUPS view [1]
  • DBA_SA_USER_LABELS view [1]
  • DBA_SA_USER_LEVELS view [1]
  • DBA_SA_USER_PRIVS view [1]
  • DBA_SA_USERS view [1]
  • default port [1]
  • default row label [1]
  • deinstallation [1]
  • DELETE_CONTROL option [1] , [2]
  • DELETERESTRICT option [1]
  • deleting labeled data [1]
  • demobld.sql file [1]
  • disabling OLS [1]
  • discretionary access control (DAC) [1]
  • distributed databases
    • connecting to [1]
    • multiple policies [1]
    • Oracle Label Security configuration [1]
    • remote session label [1]
  • dominance
    • definition [1]
    • functions
    • greatest lower bound [1]
    • inverse groups [1]
    • least upper bound [1]
    • overview [1]
  • DOMINATED_BY function [1]
  • DOMINATES function [1]
  • dropping for specified compartments [1]
  • DROP USER CASCADE restriction [1]
  • duties
    • of security administrators [1]

E

  • enabling OLS [1]
  • enforcement options
    • and UPDATE [1]
    • combinations of [1]
    • exemptions [1]
    • guidelines [1]
    • INVERSE_GROUP [1]
    • list of [1]
    • overview [1]
    • viewing [1]
  • EXEMPT ACCESS POLICY privilege [1]
  • Export utility
    • LBACSYS restriction [1]
    • policy enforcement [1]
    • row labels [1] , [2]

F


G

  • granularity
    • to data access [1]
  • GREATEST_LBOUND function
    • inverse groups [1]
  • groups
    • altering [1]
    • altering parent groups [1]
    • creating group parent [1]
    • definition [1] , [2]
    • deleting [1]
    • example [1] , [2]
    • finding for entire database [1]
    • finding hierarchy of parent-child relationships [1]
    • finding policy groups [1]
    • hierarchical [1] , [3] , [5] , [7]
    • inverse [1]
    • parent [1] , [4] , [6] , [9]
    • read/write access [1]
    • SA_COMPONENTS.ALTER_GROUP_PARENT procedure [1]
    • SA_COMPONENTS.ALTER_GROUP procedure [1]
    • SA_COMPONENTS.CREATE_GROUP procedure [1]
    • SA_COMPONENTS.DROP_GROUP [1]
    • SA_SESSION.GROUP_READ function [1]
    • SA_SESSION.GROUP_WRITE function [1]
    • SA_USER_ADMIN.ADD_GROUPS procedure [1]
    • SA_USER_ADMIN.ALTER_GROUPS procedure [1]
    • SA_USER_ADMIN.DROP_ALL_GROUPS procedure [1]
    • SA_USER_ADMIN.DROP_GROUPS procedure [1]
    • SA_USER_ADMIN.SET_GROUPS procedure [1]
    • SA_USER_ADMIN package [1]
    • setting authorizations [1] , [2]

H

  • HIDE [1] , [2] , [3]
  • HIDE option
    • default [1]
    • discussion of [1]
    • example [1]
    • importing hidden column [1]
    • inserting data [1]
    • not exported [1]
    • per-table basis [1]
    • PL/SQL restriction [1]
    • schema level [1]

I

  • impdp
    • See: Data Pump import
  • Import utility
    • importing labeled data [1] , [2]
    • importing policies [1]
    • importing unlabeled data [1]
    • with Oracle Label Security [1]
  • indexes [1]
  • INITIAL_LABEL variable [1]
  • INITIAL_ROW_LABEL variable [1]
  • initialization parameters
    • AUDIT_TRAIL [1]
  • INSERT_CONTROL option [1] , [2]
  • inserting labeled data [1] , [2]
  • INTO TABLE clause [1]
  • INVERSE_GROUP enforcement option
    • behavior of procedures [1]
    • implementation [1]
  • inverse groups
    • and label components [1]
    • COMPACCESS privilege [1] , [2]
    • computed labels [1]
    • dominance [1]
    • implementation of [1]
    • introduction [1]
    • Max Read Groups [1]
    • Max Write Groups [1]
    • parent-child unsupported [1]
    • read algorithm [1]
    • session labels [1]
    • SET_DEFAULT_LABEL [1]
    • SET_LABEL [1]
    • SET_ROW_LABEL [1] , [2]
    • user privileges [1]
    • write algorithm [1]

L

  • LABEL_DEFAULT option
    • and labeling functions [1] , [2]
    • authorizing compartments [1]
    • authorizing groups [1]
    • importing unlabeled data [1]
    • inserting labeled data [1]
    • with enforcement options [1]
    • with SA_SESSION.SET_ROW_LABEL [1]
  • LABEL_TO_CHAR function [1] , [2] , [3]
  • LABEL_UPDATE option
    • and labeling functions [1] , [2]
    • and privileges [1]
    • and WRITE_CONTROL [1]
    • and WRITEUP [1] , [4]
    • definition [1]
    • evaluation process [1]
    • with enforcement options [1]
  • label-based security [1]
  • label components
    • defining [1]
    • in distributed environment [1]
    • industry examples [1]
    • interrelation [1]
  • label evaluation process
    • COMPACCESS read [1]
    • COMPACCESS write [1]
    • inverse groups, COMPACCESS [1]
    • LABEL_UPDATE [1]
    • read access [1]
    • read access, inverse groups [1]
    • write access [1]
    • write access, inverse groups [1]
  • labeling functions
    • ALL_CONTROL and NO_CONTROL [1]
    • and CHECK_CONTROL [1]
    • and LABEL_DEFAULT [1] , [2]
    • and LABEL_DEFAULTlLABEL_DEFAULT option
      • and labeling functions [1]
    • and LABEL_UPDATE [1] , [2]
    • and LBACSYS [1]
    • creating [1]
    • example [1]
    • how they work [1]
    • importing unlabeled data [1]
    • in force [1]
    • inserting data [1]
    • introduction [1]
    • override manual insert [1]
    • specifying [1]
    • testing [1]
    • UPDATE [1]
    • using [1]
    • with enforcement options [1]
  • labels
    • administering [1]
    • altering [1]
    • and performance [1]
    • checking if a data label [1]
    • checking if changed [1]
    • creating [1]
    • data and user [1]
    • deleting [1]
    • finding greatest lower bound [1]
    • finding least upper bound [1]
    • finding tags and types of [1]
    • merging [1]
    • non-comparable [1]
    • relationships between [1]
    • restoring default for session [1]
    • SA_LABEL_ADMIN.ALTER_LABEL procedure [1]
    • SA_LABEL_ADMIN.CREATE_LABEL procedure [1]
    • SA_LABEL_ADMIN.DROP_LABEL procedure [1]
    • SA_LABEL_ADMIN package [1]
    • SA_SESSION.LABEL function [1]
    • SA_SESSION.MAX_READ_LABEL function [1]
    • SA_SESSION.MAX_WRITE_LABEL function [1]
    • SA_SESSION.MIN_WRITE_LABEL function [1]
    • SA_SESSION.RESTORE_DEFAULT_LABELS [1]
    • SA_SESSION.SET_LABEL procedure [1]
    • SA_SESSION.SET_ROW_LABEL procedure [1]
    • SA_USER_ADMIN.SET_USER_LABELS procedure [1]
    • SA_USER_ADMIN package [1]
    • SA_UTL.CHECK_LABEL_CHANGE function [1]
    • SA_UTL.GREATEST_LBOUND function [1]
    • SA_UTL.LEAST_UBOUNDfunction [1]
    • SA_UTL.SET_LABEL procedure [1]
    • saving default session label [1]
    • setting row label [1]
    • syntax [1] , [2]
    • valid [1] , [2] , [3]
    • with inverse groups [1]
  • label tags
    • converting from string [1]
    • converting to string [1]
    • distributed environment [1]
    • example [1]
    • inserting data [1]
    • introduction [1] , [2]
    • manually defined [1] , [2]
    • strategy [1]
    • using in WHERE clauses [1]
  • LBAC_LABEL data type [1]
  • LBACSYS
  • LBACSYS default user account
    • about [1]
    • best practice guideline [1]
    • enabling [1]
  • LBACSYS schema
    • and labeling functions [1]
    • creating additional databases [1]
    • data dictionary tables [1]
    • export restriction [1]
  • LEAST_UBOUND function
    • inverse groups [1]
  • levels
    • about [1]
    • altering levels [1]
    • creating [1]
    • definition [1] , [2]
    • deleting [1]
    • example [1] , [2]
    • finding [1]
    • SA_COMPONENTS.ALTER_LEVEL procedure [1]
    • SA_COMPONENTS.CREATE_LEVEL procedure [1]
    • SA_COMPONENTS.DROP_LEVEL procedure [1]
    • SA_SESSION.MAX_LEVEL function [1]
    • SA_SESSION.MIN_LEVEL function [1]
    • SA_USER_ADMIN.SET_LEVELS procedure [1]
    • setting authorizations [1] , [2]
  • logging into Oracle Label Security
    • from Cloud Control [1]
    • from SQL*Plus [1]
  • login
    • Cloud Control [1]
    • LBACSYS [1]

M

  • materialized views [1] , [2]
  • Max Read Groups [1]
  • Max Write Group [1]
  • MERGE_LABEL function [1]
  • multitenant container databases
    • See: CDBs

N

  • NO_CONTROL option [1] , [2]
  • NOAUDIT procedure [1]
  • NUMBER data type [1]

O

  • object privileges
    • and Oracle Label Security privileges [1]
    • and trusted stored program units [1] , [2]
  • OCI_ATTR_APPCTX_LIST [1]
  • OCI_ATTR_APPCTX_SIZE [1]
  • OCIAttrSet [1] , [2]
  • OCI interface [1]
  • OCIParamGet [1]
  • OLS_DOMINATED_BY function [1]
  • OLS_DOMINATES function [1]
  • OLS_GLBD function [1]
  • OLS_GREATEST_LBOUND function [1]
  • OLS_LABEL_DOMINATES function
    • about [1]
    • in Database Vault policies [1]
    • in Data Redaction policies [1]
  • OLS_LEAST_UBOUND function [1]
  • OLS_LUBD function [1]
  • OLS_STRICTLY_DOMINATED_BY function [1]
  • OLS_STRICTLY_DOMINATES function [1]
  • OptionsA [1]
  • Oracle Database Vault
    • using OLS_LABEL_DOMINATES function with [1]
  • Oracle Data Redaction
    • using OLS_LABEL_DOMINATES function with [1]
  • Oracle Enterprise Manager
    • administering labels [1]
  • Oracle Internet Directory
    • configuring OLS after switchover to standby database [1]
    • integration with OLS [1]
    • OID with Oracle Data Guard [1]
    • Oracle Label Security
      • about [1]
      • administrator duties in [1]
      • bootstrapping databases [1]
      • configuring, about [1]
      • configuring, permission for [1]
      • configuring, steps [1]
      • integrated capabilities of [1]
      • PL/SQL procedures for policy administrators [1]
      • policy attributes in [1]
      • profiles, about [1]
      • provisioning profiles, about [1]
      • provisioning profiles, changing database connection information [1]
      • provisioning profiles, managing [1]
      • removing OID-enabled OLS from database [1]
      • restrictions on new data label creation [1]
      • security roles and permitted actions [1]
      • subscribing policies in [1]
      • superseded PL/SQL statements [1]
      • synchronizing database with OID [1]
      • un-registering database [1]
  • Oracle Label Security
    • about [1]
    • benefits [1]
    • privileges required to use [1]
    • registering [1]
  • Oracle Label Security (OLS)
    • integration with Oracle Internet Directory [1]
  • Oracle Label Security data dictionary views
    • about [1]
    • ALL_SA_AUDIT_OPTIONS [1]
    • ALL_SA_COMPARTMENTS [1]
    • ALL_SA_DATA_LABELS [1] , [2]
    • ALL_SA_GROUPS [1] , [2]
    • ALL_SA_LABELS [1] , [2]
    • ALL_SA_LEVELS [1] , [2]
    • ALL_SA_POLICIES [1]
    • ALL_SA_PROG_PRIVS [1]
    • ALL_SA_SCHEMA_POLICIES [1]
    • ALL_SA_TABLE_POLICIES [1]
    • ALL_SA_USER_LABELS [1]
    • ALL_SA_USER_LEVELS [1]
    • ALL_SA_USER_PRIVS [1]
    • ALL_SA_USERS [1]
    • DBA_OLS_STATUS [1]
    • DBA_SA_AUDIT_OPTIONS [1]
    • DBA_SA_GROUP_HIERARCHY [1]
    • DBA_SA_POLICIES [1]
    • DBA_SA_PROG_PRIVS [1]
    • DBA_SA_SCHEMA_POLICIES [1]
    • DBA_SA_TABLE_POLICIES [1]
    • DBA_SA_USER_COMPARTMENTS [1]
    • DBA_SA_USER_GROUPS [1]
    • DBA_SA_USER_LABELS [1]
    • DBA_SA_USER_LEVELS [1]
    • DBA_SA_USER_PRIVS [1]
    • DBA_SA_USERS [1]
    • USER_SA_SESSION [1]
  • Oracle Label Security profiles [1]
  • ORDER BY clause [1]

P

  • packages
    • Oracle Label Security [1]
    • SA_AUDIT_ADMIN [1]
    • SA_COMPONENTS [1]
    • SA_LABEL_ADMIN [1]
    • SA_POLICY_ADMIN [1]
    • SA_SESSION [1]
    • SA_SYSDBA [1]
    • SA_USER_ADMIN [1]
    • SA_UTL [1]
    • trusted stored program units [1]
  • partitioning [1] , [2]
  • PDBs
    • Oracle Label Security [1]
  • performance, Oracle Label Security
    • ANALYZE command [1]
    • indexes [1]
    • label tag strategy [1]
    • partitioning [1]
    • READ privilege [1]
  • PL/SQL
    • recreating labels for import [1]
    • SA_UTL package [1] , [2]
    • trusted stored program units [1]
  • pluggable databases
    • See: PDBs
  • policies
    • enforcement guidelines [1]
    • enforcement options [1] , [2] , [3] , [4] , [5]
    • finding for current user [1]
    • finding for entire database [1]
    • finding information about schema policies [1]
    • finding information about table policies [1]
    • finding privileges for program units [1]
    • multiple [1] , [2]
    • OID subscription [1]
    • OID unsubscription [1]
    • privileges [1] , [2]
    • SA_POLICY_ADMIN.POLICY_SUBSCRIBE procedure [1]
    • SA_POLICY_ADMIN.POLICY_UNSUBSCRIBE procedure [1]
    • SA_POLICY_ADMIN package [1]
    • terminology [1]
  • policies, schema
    • altering [1]
    • applying [1]
    • deleting [1]
    • disabling [1]
    • enabling [1]
    • SA_POLICY_ADMIN.ALTER_SCHEMA_POLICY procedure [1]
    • SA_POLICY_ADMIN.APPLY_SCHEMA_POLICY procedure [1]
    • SA_POLICY_ADMIN.ENABLE_SCHEMA_POLICY policy [1]
    • SA_POLICY_ADMIN.REMOVE_SCHEMA_POLICY procedure [1]
  • policies, schema, disabling
    • SA_POLICY_ADMIN.DISABLE_SCHEMA_POLICY procedure [1]
  • policies, table
    • applying [1]
    • deleting [1]
    • disabling [1]
    • enabling [1]
    • SA_POLICY_ADMIN.APPLY_TABLE_POLICY procedure [1]
    • SA_POLICY_ADMIN.DISABLE_TABLE_POLICY procedure [1]
    • SA_POLICY_ADMIN.ENABLE_TABLE_POLICY procedure [1]
    • SA_POLICY_ADMIN.REMOVE_TABLE_POLICY procedure [1]
  • policy_DBA role
    • about [1]
    • auditing policy_DBA role users [1]
    • how to use [1]
    • required for Data Pump import operations [1]
    • required for label management [1]
    • required for Oracle Label Security auditing [1]
    • required for SA_USER_ADMIN.SET_PROG_PRIVS procedure [1]
    • required for SA_USER_ADMIN.SET_USER_PRIVS procedure [1]
  • policy label column
    • indexing [1]
    • inserting data when hidden [1]
    • introduction [1] , [2]
    • retrieving [1]
    • retrieving hidden [1]
    • storing label tag [1] , [2]
  • policy management
    • altering policies [1]
    • creating policies [1]
    • deleting policies [1]
    • disabling policies [1]
    • enabling policies [1]
    • SA_SYSDBA.ALTER_POLICY procedure [1]
    • SA_SYSDBA.CREATE_POLICY procedure [1]
    • SA_SYSDBA.DISABLE_POLICY procedure [1]
    • SA_SYSDBA.DROP_POLICY policy [1]
    • SA_SYSDBA.ENABLE_POLICY procedure [1]
    • SA_SYSDBA package [1]
  • predicates
    • access mediation [1]
    • errors [1]
    • label tag performance strategy [1]
    • multiple [1]
    • used with policy [1]
  • privileges
  • PROFILE_ACCESS privilege [1]
  • program units
    • finding policy privileges for [1]
  • propagated [1]

R

  • RAC [1]
  • READ_CONTROL option
    • algorithm [1]
    • and CHECK_CONTROL [1]
    • and child rows [1]
    • definition [1]
    • referential integrity [1]
    • with other options [1]
    • with predicates [1]
  • read access
  • reading down [1]
  • read label [1]
  • READ privilege [1] , [2] , [3]
  • referential integrity [1] , [2] , [3]
  • registering Oracle Label Security [1]
  • releasability [1]
  • remote users [1]
  • REPADMIN account [1] , [2] , [3]
  • replication
    • materialized views (snapshots) [1] , [2] , [3]
    • with Oracle Label Security [1] , [2]
  • replication administrator [1]
  • restrictions, Oracle Label Security [1]
  • row labels
    • default [1] , [2] , [3] , [4] , [5] , [6]
    • example [1]
    • finding current [1]
    • in distributed environment [1]
    • inserting [1]
    • LABEL_DEFAULT option [1] , [2]
    • privileges [1]
    • restoring [1]
    • SA_USER_ADMIN.SET_ROW_LABEL procedure [1]
    • SA_UTL.NUMERIC_ROW_LABEL function [1]
    • SA_UTL.SET_ROW_LABEL procedure [1]
    • saving defaults [1]
    • setting [1] , [2]
    • setting compartments [1]
    • setting for current database session [1]
    • setting for user’s initial use [1]
    • setting groups [1]
    • setting levels [1]
    • understanding [1]
    • updating [1]
    • viewing [1]

S

  • SA_AUDIT_ADMIN
    • procedures, listed [1]
  • SA_AUDIT_ADMIN.AUDIT_LABEL_ENABLED procedure [1]
  • SA_AUDIT_ADMIN.AUDIT_LABEL procedure [1]
  • SA_AUDIT_ADMIN.AUDIT procedure [1]
  • SA_AUDIT_ADMIN.CREATE_VIEW procedure [1]
  • SA_AUDIT_ADMIN.DROP_VIEW procedure [1]
  • SA_AUDIT_ADMIN.NOAUDIT_LABEL procedure [1]
  • SA_AUDIT_ADMIN PL/SQL package
  • SA_COMPONENTS
    • procedures, listed [1]
  • SA_COMPONENTS.ALTER_COMPARTMENT procedure [1]
  • SA_COMPONENTS.ALTER_GROUP_PARENT procedure [1]
  • SA_COMPONENTS.ALTER_GROUP procedure [1]
  • SA_COMPONENTS.ALTER_LEVEL procedure [1]
  • SA_COMPONENTS.CREATE_COMPARTMENT procedure [1]
  • SA_COMPONENTS.CREATE_GROUP procedure [1]
  • SA_COMPONENTS.CREATE_LEVEL procedure [1]
  • SA_COMPONENTS.DROP_COMPARTMENT procedure [1]
  • SA_COMPONENTS.DROP_GROUP procedure [1]
  • SA_COMPONENTS.DROP_LEVEL procedure [1]
  • SA_COMPONENTS package [1]
  • SA_COMPONENTS PL/SQL package
  • SA_LABEL_ADMIN
    • procedures, listed [1]
  • SA_LABEL_ADMIN.ALTER_LABEL procedure [1]
  • SA_LABEL_ADMIN.CREATE_LABEL procedure [1]
  • SA_LABEL_ADMIN.DROP_LABEL procedure [1]
  • SA_LABEL_ADMIN PL/SQL package
  • SA_POLICY_ADMIN
    • procedures, listed [1]
  • SA_POLICY_ADMIN.ALTER_SCHEMA_POLICY procedure [1]
  • SA_POLICY_ADMIN.APPLY_SCHEMA_POLICY procedure [1]
  • SA_POLICY_ADMIN.APPLY_TABLE_POLICY procedure [1]
  • SA_POLICY_ADMIN.DISABLE_SCHEMA_POLICY procedure [1]
  • SA_POLICY_ADMIN.DISABLE_TABLE_POLICY procedure [1]
  • SA_POLICY_ADMIN.ENABLE_SCHEMA_POLICY procedure [1]
  • SA_POLICY_ADMIN.ENABLE_TABLE_POLICY procedure [1]
  • SA_POLICY_ADMIN.POLICY_SUBSCRIBE procedure [1]
  • SA_POLICY_ADMIN.POLICY_UNSUBSCRIBE procedure [1]
  • SA_POLICY_ADMIN.REMOVE_SCHEMA_POLICY procedure [1]
  • SA_POLICY_ADMIN.REMOVE_TABLE_POLICY procedure [1]
  • SA_POLICY_ADMIN PL/SQL package
  • SA_SESSION
    • procedures and functions, listed [1]
  • SA_SESSION.COMP_READ function [1]
  • SA_SESSION.COMP_WRITE function [1]
  • SA_SESSION.GROUP_READ function [1]
  • SA_SESSION.GROUP_WRITE function [1]
  • SA_SESSION.LABEL function [1]
  • SA_SESSION.MAX_LEVEL function [1]
  • SA_SESSION.MAX_READ_LABEL function [1]
  • SA_SESSION.MAX_WRITE_LABEL function [1]
  • SA_SESSION.MIN_LEVEL function [1]
  • SA_SESSION.MIN_WRITE_LABEL function [1]
  • SA_SESSION.PRIVS function [1]
  • SA_SESSION.RESTORE_DEFAULT_LABELS procedure [1]
  • SA_SESSION.ROW_LABEL function [1]
  • SA_SESSION.SA_USER_NAME function [1]
  • SA_SESSION.SAVE_DEFAULT_LABELS procedure [1]
  • SA_SESSION.SET_ACCESS_PROFILE procedure [1] , [2]
  • SA_SESSION.SET_LABEL procedure
    • and SA_SESSION.RESTORE_DEFAULT_LABELS [1]
  • SA_SESSION.SET_ROW_LABEL procedure [1]
  • SA_SESSION PL/SQL package
  • SA_SYSDBA
    • procedures, listed [1]
  • SA_SYSDBA.ALTER_POLICY procedure [1]
  • SA_SYSDBA.CREATE_POLICY procedure [1]
  • SA_SYSDBA.DISABLE_POLICY procedure [1]
  • SA_SYSDBA.DROP_POLICY procedure [1]
  • SA_SYSDBA.ENABLE_POLICY procedure [1]
  • SA_SYSDBA PL/SQL package
  • SA_USER_ADMIN.ADD_COMPARTMENTS procedure [1]
  • SA_USER_ADMIN.ADD_GROUPS procedure [1]
  • SA_USER_ADMIN.ALTER_COMPARTMENTS procedure [1]
  • SA_USER_ADMIN.ALTER_GROUPS procedure [1]
  • SA_USER_ADMIN.DROP_ALL_COMPARTMENTS procedure [1]
  • SA_USER_ADMIN.DROP_ALL_GROUPS procedure [1]
  • SA_USER_ADMIN.DROP_COMPARTMENTS procedure [1]
  • SA_USER_ADMIN.DROP_GROUPS procedure [1]
  • SA_USER_ADMIN.DROP_USER_ACCESS procedure [1]
  • SA_USER_ADMIN.SET_COMPARTMENTS procedure [1]
  • SA_USER_ADMIN.SET_DEFAULT_LABEL procedure [1]
  • SA_USER_ADMIN.SET_GROUPS procedure [1]
  • SA_USER_ADMIN.SET_LEVELS procedure [1]
  • SA_USER_ADMIN.SET_ROW_LABEL procedure [1]
  • SA_USER_ADMIN.SET_USER_LABELS procedure [1]
  • SA_USER_ADMIN.SET_USER_PRIVS procedure [1]
  • SA_USER_ADMIN package
    • administering stored program units [1]
    • overview [1]
    • procedures, listed [1]
  • SA_USER_ADMIN PL/SQL package
  • SA_UTL.CHECK_LABEL_CHANGE function [1]
  • SA_UTL.CHECK_READ function [1]
  • SA_UTL.CHECK_WRITE function [1]
  • SA_UTL.DATA_LABEL function [1]
  • SA_UTL.GREATEST_LBOUND function [1]
  • SA_UTL.LEAST_UBOUND function [1]
  • SA_UTL.NUMERIC_LABEL function [1]
  • SA_UTL.NUMERIC_ROW_LABEL function [1]
  • SA_UTL.SET_LABEL procedure [1]
  • SA_UTL.SET_ROW_LABEL procedure [1]
  • SA_UTL package
    • dominance functions [1]
    • overview [1]
    • procedures and functions, listed [1]
  • SA_UTL PL/SQL package
  • schemas
    • applying policies to [1] , [2]
    • default policy options [1]
    • restrictions on shared [1]
  • session labels
    • changing [1]
    • computed [1]
    • distributed database [1]
    • example [1]
    • finding [1]
    • OCI interface [1]
    • restoring to default [1]
    • SA_UTL.SET_LABEL [1]
    • saving defaults [1]
    • setting compartments [1]
    • setting groups [1]
    • setting user initial [1]
    • understanding [1]
  • sessions
    • compartments readable by user [1]
    • compartments writeable by user [1]
    • finding current OLS user [1]
    • finding row label [1]
    • finding security attributes for [1]
    • finding session label number [1]
    • finding session privileges [1]
    • SA_SESSION.COMP_READ function [1]
    • SA_SESSION.COMP_WRITE function [1]
    • SA_SESSION.GROUP_READ function [1]
    • SA_SESSION.GROUP_WRITE function [1]
    • SA_SESSION.LABEL function [1]
    • SA_SESSION.MAX_LEVEL function [1]
    • SA_SESSION.MAX_READ_LABEL function [1]
    • SA_SESSION.MAX_WRITE_LABEL function [1]
    • SA_SESSION.MIN_LEVEL function [1]
    • SA_SESSION.MIN_WRITE_LABEL function [1]
    • SA_SESSION.PRIVS [1]
    • SA_SESSION.RESTORE_DEFAULT_LABELS procedure [1]
    • SA_SESSION.ROW_LABEL function [1]
    • SA_SESSION.SA_USER_NAME function [1]
    • SA_SESSION.SAVE_DEFAULT_LABELS procedure [1]
    • SA_SESSION.SET_ACCESS_PROFILE procedure [1]
    • SA_SESSION.SET_LABEL procedure [1]
    • SA_SESSION package [1]
    • SA_USER_ADMIN.SET_COMPARTMENTS procedure [1]
    • SA_USER_ADMIN.SET_DEFAULT_LABEL procedure [1]
    • SA_USER_ADMIN.SET_LEVELS procedure [1]
    • SA_UTL.SET_LABEL procedure [1]
    • SA_UTL.SET_ROW_LABEL procedure [1]
    • saving default session label [1]
    • setting label for [1]
    • setting OLS privileges for user [1]
    • setting row label for [1]
  • SET_ACCESS_PROFILE procedure [1]
  • SET_DEFAULT_LABEL procedure
  • SET_GROUPS procedure
    • inverse groups [1]
  • SET_LABEL procedure
    • definition [1]
    • inverse groups [1] , [2]
    • on remote database [1]
  • SET_PROG_PRIVS function [1]
  • SET_ROW_LABEL procedure
  • SET_USER_LABELS procedure
    • inverse groups [1]
  • setting label for database session [1]
  • shared schema restrictions [1]
  • SQL*Loader [1]
  • STRICTLY_DOMINATED_BY function [1]
  • STRICTLY_DOMINATES function [1]
  • SYS_CONTEXT
    • and labeling functions [1]
    • variables [1]
  • SYS account
    • policy enforcement [1]
  • SYSDBA privilege [1]
  • system privileges [1] , [2] , [3]

T

  • table rows
    • checking if user can read [1]
    • checking if user can write to [1]
    • SA_UTL.CHECK_READ function [1]
    • SA_UTL.CHECK_WRITE function [1]
  • TO_DATA_LABEL function [1] , [2]
  • TO_LBAC_DATA_LABEL function [1]
  • TO_LBAC_DATA_LABEL function, example of using [1]
  • triggers [1]
  • trusted program units
  • trusted stored program units

U

  • unified audit trail [1]
  • UPDATE_CONTROL option [1] , [2]
  • updating labeled data [1]
  • USER_SA_SESSION view [1]
  • user authorizations
    • adding for compartments [1]
    • adding for groups [1]
    • altering for compartments [1]
    • altering for groups [1]
    • compartments [1] , [2]
    • dropping for all compartments [1]
    • dropping for all groups [1]
    • dropping for specified groups [1]
    • groups [1] , [2]
    • levels [1] , [2]
    • removing all OLS privileges from user [1]
    • row labels
    • SA_USER_ADMIN.SET_USER_PRIVS procedure [1]
    • understanding [1] , [2]
  • users
    • finding label-specific information of [1]
    • finding level-specific information of [1]
    • finding policy-specific privileges of [1]
    • finding privileges of OLS users [1]
    • LBACSYS default user account [1]
  • utilities
    • SA_UTL package [1]

V

  • views
    • access mediation [1]
    • ALL_SA_AUDIT_OPTIONS [1]
    • ALL_SA_COMPARTMENTS [1]
    • ALL_SA_GROUPS [1]
    • ALL_SA_LABELS [1] , [2]
    • ALL_SA_LEVELS [1]
    • ALL_SA_POLICIES [1]
    • ALL_SA_PROG_PRIVS [1]
    • ALL_SA_SCHEMA_POLICIES [1]
    • ALL_SA_TABLE_POLICIES [1]
    • ALL_SA_USER_LABELS [1]
    • ALL_SA_USER_LEVELS [1]
    • ALL_SA_USER_PRIVS [1]
    • ALL_SA_USERS [1]
    • DBA_OLS_STATUS [1]
    • DBA_SA_AUDIT_OPTIONS [1]
    • DBA_SA_COMPARTMENTS [1]
    • DBA_SA_DATA_LABELS [1]
    • DBA_SA_GROUP_HIERARCHY [1]
    • DBA_SA_GROUPS [1]
    • DBA_SA_LABELS [1]
    • DBA_SA_LEVELS [1]
    • DBA_SA_POLICIES [1]
    • DBA_SA_PROG_PRIVS [1]
    • DBA_SA_SCHEMA_POLICIES [1] , [2]
    • DBA_SA_TABLE_POLICIES [1] , [2]
    • DBA_SA_USER_COMPARTMENTS [1]
    • DBA_SA_USER_GROUPS [1]
    • DBA_SA_USER_LABELS [1]
    • DBA_SA_USER_LEVELS [1]
    • DBA_SA_USER_PRIVS [1]
    • DBA_SA_USERS [1]

W

  • WRITE_CONTROL option
    • algorithm [1]
    • definition [1]
    • introduction [1]
    • LABEL_UPDATE [1]
    • with INSERT, UPDATE, DELETE [1]
    • with other options [1]
  • write access
  • WRITEACROSS privilege [1] , [2] , [3] , [4]
  • WRITEDOWN privilege [1] , [2] , [3] , [4]
  • write label [1]
  • WRITEUP privilege [1] , [2]