Perimeter
2/6/2013
12:38 PM
Adrian Lane
Adrian Lane
Commentary
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Restarting Database Security

Why companies ask for a database security program

"How do we put together a database security program?"

That has been the most common database security question I've received in the past nine months. I've been surprised by the number of firms that have asked for my assistance with setting up a database security program -- mostly because large firms are the ones that already have parts of a program in place. More to the point, both large and midsize firms, which have at one time bought database security products and have some database security processes, see they have a problem. The motivation for today's post is not just to relay the trend, but why companies are asking the question.

I've been talking publicly -- occasionally preaching -- about database security for the past 12 years. Database security platforms are no longer merely tools but fully mature, mainstream products. In all honesty, I thought in the evolution of database security that we were past the point of program setup, but I was wrong for a number of reasons: There are teams that broke up or stopped doing what they did due to budget. There are companies that had it, got acquired, and the parent neither had a database security program nor do existing processes from smaller firms work with the much larger parent.

In some cases companies have database security, but it's only implemented within a subset of business lines or limited to specific geographies. Some firms have database security only within one group (security, DBAs, ops), with the program limited to what the group does best (i.e.: DBAs do patching). Many limit security to specific database platforms (e.g.: Oracle experts handle Oracle, but nobody addressed MySQL, Sybase, or other platforms). And finally, companies relaxed security constraints, a little bit at a time, and then found they went too far.

And it's this latter trend that is worrisome. The trend with firms that have not been breached or suffered an "incident" is a slow and gradual pressure to relax controls. Users want additional privileges -- and they usually get what they want. DBAs don't like the hassle of providing, then revoking, privileges every few weeks. DBAs don't like having to log in under different credentials to perform granular tasks, or coordinate straightforward admin work across two or more people. It's easier to leave openings for tools and utilities that streamline tasks and make accessibility easier. It saves time and makes the job less aggravating.

Until they've been breached. Or data is exfiltrated. Or an employee abuses the database. Then everything changes.

For all of these reasons, companies need to reconsider database security. Most of the time, it's a small number of people within very large companies who understand they have a problem and are looking for guidance. They need consistency across the company. It's level-setting -- of getting everyone responsible for security and compliance on the same page about where they are and where they need to go.

So where do you start? What are the first steps in building a database security program? I'll answer that in an upcoming post.

Adrian Lane is an analyst/CTO with Securosis LLC, an independent security consulting practice. Special to Dark Reading. Adrian Lane is a Security Strategist and brings over 25 years of industry experience to the Securosis team, much of it at the executive level. Adrian specializes in database security, data security, and secure software development. With experience at Ingres, Oracle, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-3946
Published: 2014-04-24
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.

CVE-2012-5723
Published: 2014-04-24
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.

CVE-2013-6738
Published: 2014-04-24
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.

CVE-2014-0188
Published: 2014-04-24
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to...

CVE-2014-2391
Published: 2014-04-24
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potent...

Best of the Web