How Compliance Scores Are Calculated

The compliance score is a combination of severity, importance, and the percentage of
objects found to be non-compliant.

Note: Severity levels for Oracle policies available in Enterprise Manager Grid Control are defined by Oracle and cannot be changed. Administrators can manipulate importance levels on a per target basis.

Example of Lowering a Policy’s Importance Level

By default, the Password Reuse Time policy is defined with a normal importance level. This critical-level policy ensures that passwords are not being reused within a specified number of days. It could be the case that for development and test systems that are reconfigured on a frequent basis, an administrator may decide to enforce passwords that are being changed as expected but it is of lower importance for these systems than it is for production systems. For the development and test systems, the administrator may decide to lower the importance level of this policy by overriding the default importance level and specifying an importance level of Low.

Example of Increasing a Policy’s Importance Level

By default, the Default Passwords policy is defined with a normal importance level. This warning-level policy ensures that out-of-box accounts are not using out-of-box passwords; for example, the well-known combination of SCOTT/TIGER. It could be the case that for some databases it is of utmost importance to ensure that these accounts have been updated such that they do not use the default, well-known passwords. For these systems, the administrator may decide to increase the importance level of this policy by overriding the default importance level and specifying an importance level of High.

Related Topics

About Policies

About Compliance Scores

Enterprise Manager Information Roadmap