Perimeter
2/6/2013
12:38 PM
Adrian Lane
Adrian Lane
Commentary
50%
50%

Restarting Database Security

Why companies ask for a database security program

"How do we put together a database security program?"

That has been the most common database security question I've received in the past nine months. I've been surprised by the number of firms that have asked for my assistance with setting up a database security program -- mostly because large firms are the ones that already have parts of a program in place. More to the point, both large and midsize firms, which have at one time bought database security products and have some database security processes, see they have a problem. The motivation for today's post is not just to relay the trend, but why companies are asking the question.

I've been talking publicly -- occasionally preaching -- about database security for the past 12 years. Database security platforms are no longer merely tools but fully mature, mainstream products. In all honesty, I thought in the evolution of database security that we were past the point of program setup, but I was wrong for a number of reasons: There are teams that broke up or stopped doing what they did due to budget. There are companies that had it, got acquired, and the parent neither had a database security program nor do existing processes from smaller firms work with the much larger parent.

In some cases companies have database security, but it's only implemented within a subset of business lines or limited to specific geographies. Some firms have database security only within one group (security, DBAs, ops), with the program limited to what the group does best (i.e.: DBAs do patching). Many limit security to specific database platforms (e.g.: Oracle experts handle Oracle, but nobody addressed MySQL, Sybase, or other platforms). And finally, companies relaxed security constraints, a little bit at a time, and then found they went too far.

And it's this latter trend that is worrisome. The trend with firms that have not been breached or suffered an "incident" is a slow and gradual pressure to relax controls. Users want additional privileges -- and they usually get what they want. DBAs don't like the hassle of providing, then revoking, privileges every few weeks. DBAs don't like having to log in under different credentials to perform granular tasks, or coordinate straightforward admin work across two or more people. It's easier to leave openings for tools and utilities that streamline tasks and make accessibility easier. It saves time and makes the job less aggravating.

Until they've been breached. Or data is exfiltrated. Or an employee abuses the database. Then everything changes.

For all of these reasons, companies need to reconsider database security. Most of the time, it's a small number of people within very large companies who understand they have a problem and are looking for guidance. They need consistency across the company. It's level-setting -- of getting everyone responsible for security and compliance on the same page about where they are and where they need to go.

So where do you start? What are the first steps in building a database security program? I'll answer that in an upcoming post.

Adrian Lane is an analyst/CTO with Securosis LLC, an independent security consulting practice. Special to Dark Reading. Adrian Lane is a Security Strategist and brings over 25 years of industry experience to the Securosis team, much of it at the executive level. Adrian specializes in database security, data security, and secure software development. With experience at Ingres, Oracle, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5208
Published: 2014-12-22
BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, and Exaopc through R3.72.10, does not require authentication, which allows remote attackers to read arbitrary files via a RETR operation, write to arbit...

CVE-2014-7286
Published: 2014-12-22
Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local users to gain privileges via unspecified vectors.

CVE-2014-8015
Published: 2014-12-22
The Sponsor Portal in Cisco Identity Services Engine (ISE) allows remote authenticated users to obtain access to an arbitrary sponsor's guest account via a modified HTTP request, aka Bug ID CSCur64400.

CVE-2014-8017
Published: 2014-12-22
The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted request that triggers inclusion of a password in a reply, aka Bug ID CSCur41673.

CVE-2014-8018
Published: 2014-12-22
Multiple cross-site scripting (XSS) vulnerabilities in Business Voice Services Manager (BVSM) pages in the Application Software in Cisco Unified Communications Domain Manager 8 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCur19651, CSCur18555, CSCur1...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.