Perimeter
2/6/2013
12:38 PM
Adrian Lane
Adrian Lane
Commentary
50%
50%

Restarting Database Security

Why companies ask for a database security program

"How do we put together a database security program?"

That has been the most common database security question I've received in the past nine months. I've been surprised by the number of firms that have asked for my assistance with setting up a database security program -- mostly because large firms are the ones that already have parts of a program in place. More to the point, both large and midsize firms, which have at one time bought database security products and have some database security processes, see they have a problem. The motivation for today's post is not just to relay the trend, but why companies are asking the question.

I've been talking publicly -- occasionally preaching -- about database security for the past 12 years. Database security platforms are no longer merely tools but fully mature, mainstream products. In all honesty, I thought in the evolution of database security that we were past the point of program setup, but I was wrong for a number of reasons: There are teams that broke up or stopped doing what they did due to budget. There are companies that had it, got acquired, and the parent neither had a database security program nor do existing processes from smaller firms work with the much larger parent.

In some cases companies have database security, but it's only implemented within a subset of business lines or limited to specific geographies. Some firms have database security only within one group (security, DBAs, ops), with the program limited to what the group does best (i.e.: DBAs do patching). Many limit security to specific database platforms (e.g.: Oracle experts handle Oracle, but nobody addressed MySQL, Sybase, or other platforms). And finally, companies relaxed security constraints, a little bit at a time, and then found they went too far.

And it's this latter trend that is worrisome. The trend with firms that have not been breached or suffered an "incident" is a slow and gradual pressure to relax controls. Users want additional privileges -- and they usually get what they want. DBAs don't like the hassle of providing, then revoking, privileges every few weeks. DBAs don't like having to log in under different credentials to perform granular tasks, or coordinate straightforward admin work across two or more people. It's easier to leave openings for tools and utilities that streamline tasks and make accessibility easier. It saves time and makes the job less aggravating.

Until they've been breached. Or data is exfiltrated. Or an employee abuses the database. Then everything changes.

For all of these reasons, companies need to reconsider database security. Most of the time, it's a small number of people within very large companies who understand they have a problem and are looking for guidance. They need consistency across the company. It's level-setting -- of getting everyone responsible for security and compliance on the same page about where they are and where they need to go.

So where do you start? What are the first steps in building a database security program? I'll answer that in an upcoming post.

Adrian Lane is an analyst/CTO with Securosis LLC, an independent security consulting practice. Special to Dark Reading. Adrian Lane is a Security Strategist and brings over 25 years of industry experience to the Securosis team, much of it at the executive level. Adrian specializes in database security, data security, and secure software development. With experience at Ingres, Oracle, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1421
Published: 2014-11-25
mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

CVE-2014-3605
Published: 2014-11-25
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6407. Reason: This candidate is a reservation duplicate of CVE-2014-6407. Notes: All CVE users should reference CVE-2014-6407 instead of this candidate. All references and descriptions in this candidate have been removed to pre...

CVE-2014-6093
Published: 2014-11-25
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, and 8.5.x before 8.5.0 CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-6196
Published: 2014-11-25
Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSp...

CVE-2014-7247
Published: 2014-11-25
Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro Pro 2; Ichitaro 2011 Sou; Ichitaro 2012 Shou; Ichitaro 2013 Gen; and Ichitaro 2014 Tetsu allows remote attackers to execute arbitrary code via a crafted file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?