Many database security projects arrive DOA because database administrators and security pros aren't singing the same tune.
As more organizations act to protect data at its most fundamental state, within the database, one of the biggest challenges that they run into is a people problem. In order to truly mitigate data risks, security teams need to learn to not only play nice with their database administrators, but to make them meaningful stakeholders in securing the databases they're entrusted to manage. That takes education, respectful conversations, and a willingness from both parties to open their minds a bit, experts say.
"There's a shift going on where [as an industry] we're changing our database security practices and we're starting to focus on that lost realm of the database security," said Josh Shaul, CTO of Application Security. "The folks who 'own' that database, the database administrators (DBAs), are finding their worlds changing in a significant way, and some of the freedoms that they've had are being taken away from them in order to do the security stuff. From my experience, I've seen that dynamic really create a gap in understanding or perspective between the DBA and security team that often has led organizations to get stuck in the muck around the area of database security."
The perception gap stems largely from a divergence in technology backgrounds.
"Often the DBA's focus is on performance and tuning and often many of them haven't been trained on security. They do their best and they're trying to learn it on the fly," said Scott Laliberte, managing director at Protiviti. "On the flipside, a lot of the security professionals out there do not have good database skills. They tend to be operating system, network, and application folks, and you can get security folks providing recommendations that aren't real practical or can introduce a problem within the database. The DBAs, therefore, fight them very hard."
According to Larry Whiteside, CISO for Visiting Nurse Service of New York, the way a lot of security controls work necessarily require some form of performance overhead within the database. It is only natural for the kneejerk reaction from DBAs to be somewhat negative.
Role-based access control based on least user privilege is one of the most effective ways to prevent the compromise of corporate data. Our new report explains why proper provisioning is a growing challenging, due to the proliferation of "big data," NoSQL databases, and cloud-based data storage. Download the report now. (Free registration required.)
Published: 2015-08-30 The IPsec SA establishment process on Innominate mGuard devices with firmware 8.x before 8.1.7 allows remote authenticated users to cause a denial of service (VPN service restart) by leveraging a peer relationship to send a crafted configuration with compression.
Published: 2015-08-30 Buffer overflow in the HTTP administrative interface in TIBCO Rendezvous before 8.4.4, Rendezvous Network Server before 1.1.1, Substation ES before 2.9.0, and Messaging Appliance before 8.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vect...
Published: 2015-08-30 Cross-site request forgery (CSRF) vulnerability in the web server on Siemens SIMATIC S7-1200 CPU devices with firmware before 4.1.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Published: 2015-08-29 Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token...
Published: 2015-08-29 The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point i...