![]() |
Data security and privacy: A holistic approach Download here |
Sponsored by AppSec and independently researched and written by Adrian Lane, analyst and CTO and Rich Mogull, analyst and CEO of Securosis, the guide to securing databases is titled, "Measuring and Optimizing Database Security and Compliance Operations: An Open Model". Dubbed by Securosis as "DB Quant" (short for Database Security Quant Research Project), the guide provides insight into all common database security tasks, with the goal of equipping organizations with a tool to better understand the security costs of configuring, monitoring and managing databases.
"Despite being the most important repositories for the most sensitive and critical data, the ongoing, multi-year spate of data breaches proves that most organizations still struggle to effectively secure databases," said Rich Mogull. "So when AppSec pointed out the need for an independent model for measuring the costs of database security, we were excited about creating what we believe has become the first totally objective, comprehensive database security program framework."
"Database security encompasses a large number of processes managed by different teams -- from database administrators (DBAs), to security operations, to IT operations, really running the gamut of operational staff," said Adrian Lane. "Our research has uncovered a consistent set of processes every IT team goes through to secure their databases, and each has a quantifiable cost associated with it. Thus with DB Quant, organizations can now model their database security program, in terms of costs and effectiveness."
With this in mind, DB Quant contains six major phases, with 21 sub-processes and dozens of operational metrics presented in an 80-page guide. The highlights are also available in an Executive Summary packaging, hitting the highlights of the process. Some of the key findings of the 18-month long research project include:
At the time this project started, there were no standardized processes for database security in the industry.
Staff time for setup tasks and policy management represents the majority of costs.
Auditors and operations management personnel - responsible for regulatory mandates and industry compliance - followed the same set of security processes.
There is a great divide in the depth and complexity of the processes used by mid-market (less than $1B revenue) companies and large enterprises.
While the processes vary by company size, key metrics that embody the majority of costs tend to be the same.
"The industry lacked and sorely needed an independent look at what it truly costs to secure a database, from soup to nuts, as well as a guide to help practitioners better understand all of the aspects of protecting the database," said Thom VanHorn, Vice President of Marketing, AppSec. "We believe the tremendous work that Securosis put into DB Quant represents the most significant step forward in helping companies get their arms around a very complex situation in an easy to understand format. We expect this to serve as the standard database security framework moving forward."
Webinar and Report Information: AppSec will be hosting a webinar with Adrian Lane and Rich Mogull of Securosis, who will share a behind the scenes look at the creation of "DB Quant", why it was a project that they engaged in, what the content of the guide entails and how to best use the information.
Title: Measuring and Optimizing Database Security and Compliance Operations Date: Tuesday, April 26, 2011 Time: 2:00 PM - 3:00 PM EDT Register: https://www1.gotomeeting.com/register/234255137
Download a free copy of the guide: "Measuring and Optimizing Database Security and Compliance Operations: An Open Model".
About Securosis Securosis is an information security research and advisory firm dedicated to transparency, objectivity, and quality. We are totally obsessed with improving the practice of information security. Our job is to save you money and help you do your job better and faster by helping you cut through the noise and providing clear, actionable, pragmatic advice on securing your organization. For more information, please visit: www.securosis.com.
About Application Security, Inc. AppSec is the leading provider of database security, risk and compliance (SRC) solutions for the enterprise. AppSec's agentless approach - AppDetectivePro for auditors and IT advisors, and DbProtect for the enterprise - delivers the industry's most scalable database SRC solution and is in use around the world in the most demanding environments by over 2,000 customers. The company was named to Inc. Magazine's 2007 (Inc. 500) and 2008 list of America's Fastest Growing Private Companies, and was also named to the 2008 Deloitte Technology Fast 50 by Deloitte & Touche.
For more information, please visit www.appsecinc.com | www.teamshatter.com
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Securing The Data Warehouse
Many enterprises are building data warehouses to centralize the ever-increasing information flowing through their organizations into useful repositories. This makes good business sense, but it opens up a slew of concerns from a security standpoint. IT professionals can apply many of the same security best practices used with databases, but there are new lessons to be learned as well.
Defend Your Data From Malicious Insiders
The biggest threat to your company?s most sensitive data may be the employee who has legitimate access to corporate databases but less-than-legitimate intentions. And while the incidence of insider data breaches has decreased, external attacks often imitate them--and do serious damage. Follow our advice to mitigate the risk.
Ensuring Secure Database Access
Role-based access control based on least user privilege is one of the most effective ways to prevent the compromise of corporate data. But proper provisioning is a growing challenging, due to the proliferation of "big data," NoSQLdatabases, and cloud-based data storage.
Other reports from the Database Security Tech Center:
| Sponsored by: |
Establishing a Strategy for Database Security is No Longer Optional
As databases continue to grow in size, complexity and importance, enterprises struggle to identify the most appropriate controls regarding their use and misuse. The report identifies best practices, including: Implementing database activity monitoring to mitigate the high levels of risk from database vulnerabilities, and address audit findings in areas such as database segregation of duties and change management; using data security measures, such as data masking and data encryption; and monitoring privileged-user access and access to critical data.
Database Activity Monitoring Is Evolving Into Database Audit and Protection
In this report, Gartner writes that "Database audit and protection (DAP) represents an evolutionary advance in database activity monitoring tools." DAP suites provide comprehensive, cross-platform support in heterogeneous database environments to protect sensitive data from inappropriate use. Organizations are increasingly concerned with optimizing database security and mitigating risks associated with database vulnerabilities.
Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
Data security presents a multi-dimensional challenge in today's complex IT environment. Multiple access paths and permission levels have resulted in a broad array of security threats and vulnerabilities. We invite you to read this new eBook: "Protecting against database attacks and insider threats" to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
Demo: Distributed Database Security with Real-time Monitoring and Audit Protection
Organizations across the globe continue to experience compromised data caused by malicious attacks, web application vulnerabilities or unauthorized changes. View this demo and learn how IBM InfoSphere Guardium? database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.
Look Beyond Native Database Auditing To Improve Security, Audit Visibility, And Real-Time Protection
Today's attacks on enterprise databases are more sophisticated than ever, and they occur so fast that it's often difficult to stop them in real time. Despite significant efforts to protect enterprise databases, the number of records breached has grown each year - due to all types of internal and external attacks and violations of corporate policy.
MORE NEWSFEED >>>