![]() |
Data security and privacy: A holistic approach Download here |
“Network-based file activity monitoring alone cannot peer into local console-based access and may not be cost-effective for remote locations, creating blind spots for many enterprises,” explained Neil MacDonald VP and Gartner Fellow. “Comprehensive file monitoring must support both agent and network-based approaches for complete coverage.”
SecureSphere 8.5 adds Windows File Server agents as a deployment option. Agents can be used in conjunction with SecureSphere File Security appliances to optimize deployments based on network topology and business needs. Key capabilities include:
Enables privileged user monitoring and separation of duties through visibility into administrative and all other local activity;
Provides clear visibility into user identities and access activity in encrypted networks;
Supports efficient auditing of distributed file servers in multiple data centers or branch offices.
In addition, SecureSphere 8.5 will include new agent-based monitoring and auditing for DB2 z/OS mainframe databases. The mainframe agent delivers a comprehensive and efficient solution for auditing database activities and addressing regulatory requirements related to critical mainframe systems. Key capabilities include:
Complete visibility into critical operations, including: SELECTS, DML and DDL, privileged activities and DB2 utilities;
Offloads processing to zIIP processors to minimize impact on total cost of mainframe computing;
Generates real-time alerts on policy violations and security events;
Fully integrated into the SecureSphere suite for cross-platform audit management.
Finally, SecureSphere 8.5 optimizes agent-based monitoring and auditing for open systems databases. The SecureSphere database agents are designed to minimize monitoring overhead and are deployed and upgraded without the need to restart target databases. SecureSphere architecture scales to support large number of agents delivering thousands of transactions per second of audited data. Agent-based monitoring can cover local traffic or all traffic and can be combined with network based monitoring for highly optimized database security deployment.
“With this release, Imperva expands the industry’s most comprehensive data security suite,” said Imperva CTO Amichai Shulman. “With our agent technology, Imperva gives enterprises the most complete solution to protect data as it moves from database to files and applications.”
SecureSphere 8.5 is available immediately for customer deployments. Certain features are scheduled for release in Q2 2011; please contact Imperva Sales for further information. About Imperva
Imperva is the global leader in data security. With more than 1,300 direct customers and 25,000 cloud customers, Imperva's customers include leading enterprises, government organizations, and managed service providers who rely on Imperva to prevent sensitive data theft from hackers and insiders. The award-winning Imperva SecureSphere is the only solution that delivers full activity monitoring for databases, applications and file systems. For more information, visit www.imperva.com, follow us on Twitter or visit our blog.
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Securing The Data Warehouse
Many enterprises are building data warehouses to centralize the ever-increasing information flowing through their organizations into useful repositories. This makes good business sense, but it opens up a slew of concerns from a security standpoint. IT professionals can apply many of the same security best practices used with databases, but there are new lessons to be learned as well.
Defend Your Data From Malicious Insiders
The biggest threat to your company?s most sensitive data may be the employee who has legitimate access to corporate databases but less-than-legitimate intentions. And while the incidence of insider data breaches has decreased, external attacks often imitate them--and do serious damage. Follow our advice to mitigate the risk.
Ensuring Secure Database Access
Role-based access control based on least user privilege is one of the most effective ways to prevent the compromise of corporate data. But proper provisioning is a growing challenging, due to the proliferation of "big data," NoSQLdatabases, and cloud-based data storage.
Other reports from the Database Security Tech Center:
| Sponsored by: |
Establishing a Strategy for Database Security is No Longer Optional
As databases continue to grow in size, complexity and importance, enterprises struggle to identify the most appropriate controls regarding their use and misuse. The report identifies best practices, including: Implementing database activity monitoring to mitigate the high levels of risk from database vulnerabilities, and address audit findings in areas such as database segregation of duties and change management; using data security measures, such as data masking and data encryption; and monitoring privileged-user access and access to critical data.
Database Activity Monitoring Is Evolving Into Database Audit and Protection
In this report, Gartner writes that "Database audit and protection (DAP) represents an evolutionary advance in database activity monitoring tools." DAP suites provide comprehensive, cross-platform support in heterogeneous database environments to protect sensitive data from inappropriate use. Organizations are increasingly concerned with optimizing database security and mitigating risks associated with database vulnerabilities.
Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
Data security presents a multi-dimensional challenge in today's complex IT environment. Multiple access paths and permission levels have resulted in a broad array of security threats and vulnerabilities. We invite you to read this new eBook: "Protecting against database attacks and insider threats" to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
Demo: Distributed Database Security with Real-time Monitoring and Audit Protection
Organizations across the globe continue to experience compromised data caused by malicious attacks, web application vulnerabilities or unauthorized changes. View this demo and learn how IBM InfoSphere Guardium? database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.
Look Beyond Native Database Auditing To Improve Security, Audit Visibility, And Real-Time Protection
Today's attacks on enterprise databases are more sophisticated than ever, and they occur so fast that it's often difficult to stop them in real time. Despite significant efforts to protect enterprise databases, the number of records breached has grown each year - due to all types of internal and external attacks and violations of corporate policy.
MORE NEWSFEED >>>