What is our primary use case?
We use this solution primarily for GDPR and PCI compliance for the bank.
How has it helped my organization?
We were implementing this solution for our client, who was required to do PCI compliance. Their project was initially scheduled to run over a year and a half, but by just deploying this product they were able to do the compliance reports within three months, so the time to roll out was quite significant. The time was very short, which meant the turnaround time for compliance was much shorter and the value was realized, so that is one positive aspect that we experienced with our clients.
What is most valuable?
The most valuable feature is the ability to create inbuilt reports for compliance, which have dealt with the rules made it easier. This means that we don't have to develop them from scratch, which makes life so much easier.
What needs improvement?
One of the biggest challenges that we are facing is the inability to use more than one account for the platform, so the whole organization cannot make their own compliance audits at their own pace. I think that's one feature that really is giving us a bit of a problem. That is one of our biggest challenges.
The fact that it doesn't audit the network is also quite a downfall for the product. Maybe it should be improved to allow one to log on to network devices and do audits to check compliance at that level.
Finally, the ability to integrate with well-known applications like SAP, Microsoft, and common ERP would be helpful. If it included templates that are used for audits that can be used in those platforms and checking compliance, that would be really helpful, because half the time there isn't enough documentation to help someone check the compliances of specific applications. The second bit is the ability to audit middleware, like application servers and spatial and detection platforms. That is quite lacking in this product.
For how long have I used the solution?
We've been using this solution since 2011.
What do I think about the stability of the solution?
It's not a stable product, especially around log management and log generation. There are lots of logs and the administration or management is not as easy as one would expect. So you need a lot of DBA and unique skills in order to handle the virtual appliances. For us it was in our domain, but I don't think for any other organization it would be easy to readminister, especially when cable spaces are full and there are other challenges.
What do I think about the scalability of the solution?
It's very scalable. It can do real application, remote sites, and DR, so it's quite scalable. I think it's very easy to scale from that test; I think they've done well.
We've got at least 60 users, including IT demonstrators, auditors, and the risk department, so it's widely used.
It's currently used extensively at the bank because they have to measure their compliance in real time and they cannot do that without this solution. There were plans to integrate the solution with the ERT to start looking at certain components within ERT, as well as opportunities for them to expand it to be used on their distributions. I'm not too sure how far they have gone because we just deployed and left. We've not been back to these clients for this product so far.
How are customer service and technical support?
Oracle does not have very good documentation on this. I think Oracle abandoned the product, especially on the support side. It's not really one of the most friendly platforms where you can actually find help, but we've hung in there. We hope there will be a lot more opportunities for them to improve the support, half the people you talk to don't really know how to support the product. It's just frustrating, honestly.
The documentation is there, if very basic, but it doesn't help you address some of the more technical challenges.
Which solution did I use previously and why did I switch?
I had not used any other solution before Oracle. We deployed this particular solution because we are required to do PCI compliance. I don't think they could have used any other solution for this, without resorting to using lots of Excel sheets, reports, etc.
How was the initial setup?
It was very straightforward to set up, not too complex.
What about the implementation team?
Deployment took a month, and then the next month we set up the reports. However, the technical deployment took us only two weeks to do, including both the products and the development of the appliances. Our strategy was to deploy as is, using the standard report and customize the report as we go, instead of trying to come up with custom reports before deployment. That made it much easier, while still being adequate to satisfy the compliance department.
We are an integrator and our name is Making Solutions. So we are the ones who did the job. I only have three guys running the platform, so its quite easy to manage. From the client's staff, there are only two guys managing the platform.
What was our ROI?
They have had a good ROI because they were literally being audited and given lots of fines. All those things have disappeared within eight months. They were able to comply, submit reports on time, and actively correct whatever mistakes were picked up by the product. We use Oracle Enterprise Manager, which looks at other components to really add all the valuable information.
What's my experience with pricing, setup cost, and licensing?
For the bank, the licensing cost is about $360,000, annually.
For the value and cost of being compliant, the price is worth paying, because then you don't get auditors coming in left, right and center. Our clients spend a lot of money, but they also get their compliance guaranteed, so I think it's overall saving them money.
There are no additional fees to pay.
Which other solutions did I evaluate?
Our client did check another provider. I forgot the name of that product, but it was a big competitor of Oracle's solution.
What other advice do I have?
Those who want to implement it better have a proper detection in place, especially regarding documents. That's one thing that really drove us nuts because without having reference documentation of the platforms that they were targeting, it became a nightmare.
I would rate this solution as eight out of ten, because of the previous reasons that I gave around some of the features that are important for my clients. If it was not for that I would have given it a ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.