Oracle Information Protection Policy

Overview

Oracle’s formal Information Protection Policy sets forth the requirements for classifying and handling public and confidential information.

Oracle categorizes information into four classes—Public, Internal, Restricted, and Highly Restricted—with each classification requiring corresponding levels of security controls, such as encryption requirements for non-Public data:

  • “Public” information is not sensitive and is not considered confidential to Oracle.
  • “Oracle Internal” information must remain confidential to Oracle.
  • “Oracle Restricted” and “Oracle Highly Restricted” information must remain confidential to Oracle and access within Oracle must be restricted on a “need to know” basis, with additional handling requirements for “Oracle Highly Restricted” information.

Training and Awareness

Oracle’s mandatory training instructs employees about the company’s Information Protection Policy. This training also tests employee understanding of information asset classifications and handling requirements. Employees must complete this training when joining Oracle and must periodically repeat it thereafter. Reports enable managers to track course completion for their organizations.

Oracle Data Management and Retention

Oracle has formal requirements for managing data retention. These operational policies define requirements per data type and category, including examples of records in various Oracle departments.

System Inventory

Developing and maintaining accurate system inventory is a necessary element for effective general information systems management and operational security. Oracle’s Information Systems Asset Inventory Policy requires that Line of Business (LoB) maintain accurate and comprehensive inventories of information systems, hardware and software. This policy applies to all information assets held on any Oracle system, including both enterprise systems and cloud services.

Oracle policy specifies the data (or fields) which must be maintained about these information systems in the approved system inventory. The required technical and business information fall in the following categories:

  • Hardware details such as manufacturer, model number and serial number of the equipment, system or device
  • Physical location of the data center/facility and location within that building
  • Software details such as the applications and associated versions
  • Classification of information assets
  • Ownership information at the organizational level.

注:为免疑义,本网页所用以下术语专指以下含义:

  1. 除Oracle隐私政策外,本网站中提及的“Oracle”专指Oracle境外公司而非甲骨文中国。
  2. 相关Cloud或云术语均指代Oracle境外公司提供的云技术或其解决方案。