As part of a SOX requirement we want to implement the recommendations in "Best Practices for Securing Oracle E-Business Suite - Version 3.0.5" as noted below. This recommends two profiles for password management. Just wondering if others have done this and if so what is the best method? We are experimenting now but thought someone might be able to provide some insight, or warnings, that we may need to consider. Any details on how you implemented this would be appreciated. Thanks!
IMPLEMENT TWO PROFILES FOR PASSWORD MANAGEMENT
The database provides parameters to enforce password management policies. However, some of the database password policy parameters could lock-out the E-Business Suite. Because of this, we make specific recommendations for or against using certain management features depending upon schema type.