![]() |
Practical Guide to Database Security Download here |
Sep 18, 2009 | 03:47 PM
By John SawyerMost businesses thrive on partnerships, and some businesses -- well, they simply can't exist without partners. But sometimes those relationships pose a real threat to your company's security.
A recent Verizon Business study of more than 500 data breaches during the past four years drives that point home. In the study, 57 percent of data breaches involved partners' networks being used by an external attacker.
Enabling contractors, suppliers, and other business partners access to your network does not have to be a recipe for disaster. To be successful, you need to know where your data is and who needs to access it. Only then can you plan your network and remote access infrastructure so it can be monitored and protected comprehensively.
The most important factor to remember during the process of enabling and securing partner connections is that your partners are third parties accessing your network. They are not your employees. You don't control their networks. You should treat them as untrusted, possibly malicious, entities who must be there, but might need to be removed at any time. You are the digital bouncer.
Before providing outsiders access to your environment, you must know which data they will need, where it's located, and how to allow just enough access for them to do their jobs. This is the part where most companies fall down. It sounds simple, but you need only look at recent partner-related breach news to see that many companies are doing it wrong.
Many of these breaches happen because of a disconnect between IT and the people behind the partner-related business processes. For example, say someone from purchasing requests access for a supplier to an internal, Web-based inventory application. IT configures a new VPN connection, sets the appropriate firewall rules, and marks the request as complete.
Unfortunately, it doesn't end there. Often, a request comes back that the supplier needs additional access to another system. After a back-and-forth between IT, the partner, and the business unit, management tells IT to "get it done or else." Now the company's sensitive systems are opened too much, so that the link works and management is happy. Sound familiar?
If IT had a better understanding of where the data is and who uses it, then the process of allowing and controlling that access would be greatly improved. A database activity monitoring (DAM) tool, for example, can provide insight into which users are accessing what data. Most can be configured to establish a baseline for what is normal -- and alert IT of any abnormalities.
In the case of a partner, policies can be defined in a DAM that say partner X is allowed to connect from network Y only during business hours and only to table Z in the database. Any deviations from that policy can be either blocked or flagged, depending on the features of the DAM product.
Page 2: A common problem that plagues enterprises.
![]()
1
|
2
Next Page »
Inside Out: Protecting Your Partnerships -- and Your Data
Today's businesses depend on e-commerce among partners, but allowing third parties to access internal networks may endanger your data. How can IT security pros ensure that contractors, supplies and others get the access they need -- without becoming threats? This report offers some answers.
Rotten Apples: How To Detect And Stop Malicious Insiders In Your Organization
Most data leaks are unintentional - but in every enterprise, there are a few hard cases that defy this truism and threaten the very heart of your data.What can you do to stop these rotten apples from using their intimate knowledge of your organization - and its data access methods - to wreak havoc? This report offers a detailed look at how malicious insiders might attack your data, how they’re motivated, and what you can do to stop them.
Understanding The Insider Threat
Think you know your trusted users? Think again. The availability of new Internet technologies and the pressures of a spiraling economy are changing the nature of the data breach, and your employees may have their fingers on the trigger. This report offers a look at the full spectrum of insider threats, and the risks associated with each.
Well-Meaning Employees -- And How To Stop Them
The most dangerous threat to your data isn't hackers or criminal insiders: it's the well-meaning employee, whose missteps may lead to the unintentional leak of your most sensitive corporate data. Learn how employees accidentally expose sensitive information, and how you can keep those good intentions from paving the road to your company's ruin.
MORE NEWSFEED >>>