Oracle
Sitefinder
    WorldwideChange Country, Oracle Worldwide Web Sites
Secure Search

Secure Development Process

Oracle's secure development process ensures that product security standards are state-of-the-art and applied uniformly throughout the company, and that standard security tools and software libraries are always implemented. Oracle's goal is to ensure that all of its developers are "security aware" at every step of the development process—from product definition and development through product release and maintenance.

BENEFITS

  • Secure by design—The secure development process applies to all phases of design and development significantly minimizing the risk of major security holes in all Oracle products.
  • Ongoing assurance—Security tests are conducted during all phases of development and even after the release of the software. Vulnerabilities to emerging threats are also periodically reassessed. Oracle is committed to remediating security vulnerabilities in its products through the Critical Patch Update.
  • External validation—Oracle is committed to external security validations such as Common Criteria and FIPS 140-2 (for cryptographic modules). This ensures that Oracle products are thoroughly tested to meet independently determined security baselines.

SECURITY LIFECYCLE PROCESS

Product Definition
The secure development processes begin long before Oracle developers start building products. Oracle actively maintains a set of secure coding standards, as well as sets of libraries for security functions such as authentication and cryptography. Developers use these libraries to ensure secure design and avoid errors in implementation. To ensure that standards are uniformly adopted, Oracle provides security standards training for all its developers, product managers, release managers, and quality assurance staff.

Product Development
During the software development processes, Oracle incorporates a myriad of security tests, including:

  • Attempts to break ("hack") its security mechanisms by experts within and outside its development teams
  • Testing via specialized security vulnerability analysis tools, including comprehensive source code analysis capabilities
  • Extensive security checklists to revalidate adherence to security standards throughout the development process
  • Independent, third-party security evaluations by government and industry organizations

Ongoing Assurance
Oracle ships its products with up-to-date best-practices documents for secure configurations and deployments in the real world. When security vulnerabilities are uncovered, fixes are:

  • Addressed in the main code so the most recent Oracle products have the greatest level of security
  • Delivered via Critical Patch Update to customers deploying earlier versions of Oracle products
  • Updated in Oracle's security standards in light of the new "lessons learned"
email this page E-mail this page printer view Printer View
Oracle Is The Information Company About Oracle | Oracle RSS Feeds | Subscribe | Careers | Contact Us | Site Maps | Legal Notices | Terms of Use | Your Privacy Rights