Skip to Main Content

Azure

Security CapabilityOracle Exadata Database Service on Dedicated InfrastructureOracle Exadata Database Service on Exascale InfrastructureOracle Autonomous AI Database ServerlessOracle Base Database ServiceNotes
Data Safe Y Y Y Y Includes up to 1 million free audit records per database per month with storage for up to seven years. If the 1 million records per month limit is exceeded, there is a small fee for excess audit consumption.
Control privileged users, including DBAs (Database Vault) Y Y Y Y BaseDB requires High Performance edition
SQL Firewall (Database Vault) Y Y Y Y BaseDB requires High Performance edition
Label-based mandatory access control at the row level (Label Security) Y Y Y Y BaseDB requires High Performance edition
Real Application Security Y Y Y Y
Virtual Private Database Y Y Y Y
Transparent Data Encryption (TDE) for Tablespaces (Advanced Security) Y Y Y Y
Ability to Set the Default Tablespace Encryption Algorithm (Advanced Security) Y Y N Y
Transparent Data Encryption (TDE) for Columns (Advanced Security) Y Y Y Y
Data Redaction (Advanced Security) Y Y Y Y BaseDB requires High Performance edition
Keystore for Each Pluggable Database (Advanced Security) Y Y N Y
Sharing of TDE Master Encryption Key Across Oracle Processes (Advanced Security) Y Y Y Y
Encrypted Data Pump exports (Advanced Security) Y Y Y Y
Control and manage encryption keys (Key Vault) Y Y Y Y
Install and operate within this cloud (Key Vault) Y Y N Y Product license required, install in Azure is supported.
Control and manage encryption keys (Azure Key Vault) Y Y Y Y
Centrally Managed Users Y Y Y Y
Enterprise User Security Y Y N Y
OCI IAM Authentication N N N N
Microsoft EntraID Authenticaiton Y Y Y Y
Local user MFA using OCI IAM Y Y N Y
Local user MFA using Cisco DUO Y Y N Y
Collect audit data for analysis, alerting, and reporting (Audit Vault and Database Firewall) Y Y Y Y Collect audit data for analysis, alerting, and reporting
Assess security posture and user risk. Detect configuration and entitlement drift (Audit Vault and Database Firewall) Y Y Y Y Configuration and entitlement assessment with drift detection and alerting
Audit Vault and Database Firewall: Install natively in this cloud (Audit Vault and Database Firewall) N N N N Cannot be installed in Azure, but if installed in a supported cloud (OCI, AWS) or on-premises can work with databases running in Azure
Unified Auditing Y Y Y Y
Fine-grained Auditing Y Y Y Y
Privilege Analysis Y Y Y Y
Transparent Sensitive Data Protection Y Y Y Y
  • 1 - 29

Google Cloud

Security CapabilityOracle Exadata Database Service on Dedicated InfrastructureOracle Autonomous AI Database ServerlessOracle Exadata Database Service on Exascale InfrastructureOracle Base Database ServiceNotes
Data Safe Y Y Y Y Includes up to 1 million free audit records per database per month with storage for up to seven years. If the 1 million records per month limit is exceeded, there is a small fee for excess audit consumption.
Control privileged users, including DBAs (Database Vault) Y Y Y Y BaseDB requires High Performance edition
SQL Firewall (Database Vault) Y Y Y Y BaseDB requires High Performance edition
Label-based mandatory access control at the row level (Label Security) Y Y Y Y BaseDB requires High Performance edition
Real Application Security Y Y Y Y
Virtual Private Database Y Y Y Y
Transparent Data Encryption (TDE) for Tablespaces (Advanced Security) Y Y Y Y
Ability to Set the Default Tablespace Encryption Algorithm (Advanced Security) Y N Y Y
Transparent Data Encryption (TDE) for Columns (Advanced Security) Y Y Y Y
Data Redaction (Advanced Security) Y Y Y Y BaseDB requires High Performance edition
Keystore for Each Pluggable Database (Advanced Security) Y N Y Y
Sharing of TDE Master Encryption Key Across Oracle Processes (Advanced Security) Y Y Y Y
Encrypted Data Pump exports (Advanced Security) Y N Y Y
Control and manage encryption keys (Key Vault) Y Y Y Y
Install and operate within this cloud (Key Vault) Y Y Y Y License required, install in GCP supported
Centrally Managed Users Y Y Y Y
Enterprise User Security Y N Y Y
OCI IAM Authentication N N N N
Microsoft EntraID Authenticaiton Y Y Y Y
Local user MFA using OCI IAM Y N Y Y
Local user MFA using Cisco DUO Y N Y Y
Collect audit data for analysis, alerting, and reporting (Audit Vault and Database Firewall) N Y Y Y Collect audit data for analysis, alerting, and reporting
Assess security posture and user risk. Detect configuration and entitlement drift (Audit Vault and Database Firewall) Y Y Y Y Configuration and entitlement assessment with drift detection and alerting
Audit Vault and Database Firewall: Install natively in this cloud (Audit Vault and Database Firewall) N N N N Cannot be installed in GCP, but if installed in a supported cloud (OCI, AWS) or on-premises can work with databases running in GCP
Unified Auditing Y Y Y Y
Fine-grained Auditing Y Y Y Y
Privilege Analysis Y Y Y Y
Transparent Sensitive Data Protection Y Y Y Y
  • 1 - 28

AWS

Security CapabilityOracle Exadata Database Service on Dedicated InfrastructureOracle Autonomous Database DedicatedNotes
Data Safe Y Y Includes up to 1 million free audit records per database per month with storage for up to seven years. If the 1 million records per month limit is exceeded, there is a small fee for excess audit consumption.
Control privileged users, including DBAs (Database Vault) Y Y BaseDB requires High Performance edition. Not available in RDS
SQL Firewall (Database Vault) Y Y BaseDB requires High Performance edition. Not available in RDS
Label-based mandatory access control at the row level (Label Security) Y Y BaseDB requires High Performance edition
Real Application Security Y Y
Virtual Private Database Y Y
Transparent Data Encryption (TDE) for Tablespaces (Advanced Security) Y Y
Ability to Set the Default Tablespace Encryption Algorithm (Advanced Security) Y Y
Transparent Data Encryption (TDE) for Columns (Advanced Security) Y Y
Data Redaction (Advanced Security) Y Y BaseDB requires High Performance edition
Keystore for Each Pluggable Database (Advanced Security) Y N
Sharing of TDE Master Encryption Key Across Oracle Processes (Advanced Security) Y Y
Encrypted Data Pump exports (Advanced Security) Y Y
Control and manage encryption keys (Key Vault) Y Y
Install and operate within this cloud (Key Vault) Y Y License required, install in AWS supported
Control and manage encryption keys (AWS Key Vault) Y Y
Centrally Managed Users Y Y
Enterprise User Security Y N
OCI IAM Authentication N N
Microsoft EntraID Authenticaiton Y Y
Local user MFA using OCI IAM Y N
Local user MFA using Cisco DUO Y N
Collect audit data for analysis, alerting, and reporting (Audit Vault and Database Firewall) Y Y Collect audit data for analysis, alerting, and reporting
Assess security posture and user risk. Detect configuration and entitlement drift (Audit Vault and Database Firewall) Y Y Configuration and entitlement assessment with drift detection and alerting
Audit Vault and Database Firewall: Install natively in this cloud (Audit Vault and Database Firewall) Y Y AWS-native AMI image available from the Oracle software delivery cloud
Unified Auditing Y Y
Fine-grained Auditing Y Y
Privilege Analysis Y Y
Transparent Sensitive Data Protection Y Y
  • 1 - 29