Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


01:10 PM
Dark Reading
Dark Reading
Products and Releases

AppSec And Securosis Team Up To Provide Comprehensive Guide For Database Security Programs

Guide provides insight into all common database security tasks

NEW YORK and PHOENIX - April 12, 2011 - Application Security, Inc. (AppSec), the leading provider of database security, risk and compliance solutions (SRC) for the enterprise and independent research and analysis firm Securosis, today announced the availability of the industry’s first comprehensive guide to quantifying enterprise database security processes.

Sponsored by AppSec and independently researched and written by Adrian Lane, analyst and CTO and Rich Mogull, analyst and CEO of Securosis, the guide to securing databases is titled, "Measuring and Optimizing Database Security and Compliance Operations: An Open Model". Dubbed by Securosis as "DB Quant" (short for Database Security Quant Research Project), the guide provides insight into all common database security tasks, with the goal of equipping organizations with a tool to better understand the security costs of configuring, monitoring and managing databases.

"Despite being the most important repositories for the most sensitive and critical data, the ongoing, multi-year spate of data breaches proves that most organizations still struggle to effectively secure databases," said Rich Mogull. "So when AppSec pointed out the need for an independent model for measuring the costs of database security, we were excited about creating what we believe has become the first totally objective, comprehensive database security program framework."

"Database security encompasses a large number of processes managed by different teams -- from database administrators (DBAs), to security operations, to IT operations, really running the gamut of operational staff," said Adrian Lane. "Our research has uncovered a consistent set of processes every IT team goes through to secure their databases, and each has a quantifiable cost associated with it. Thus with DB Quant, organizations can now model their database security program, in terms of costs and effectiveness."

With this in mind, DB Quant contains six major phases, with 21 sub-processes and dozens of operational metrics presented in an 80-page guide. The highlights are also available in an Executive Summary packaging, hitting the highlights of the process. Some of the key findings of the 18-month long research project include:

At the time this project started, there were no standardized processes for database security in the industry.

Staff time for setup tasks and policy management represents the majority of costs.

Auditors and operations management personnel - responsible for regulatory mandates and industry compliance - followed the same set of security processes.

There is a great divide in the depth and complexity of the processes used by mid-market (less than $1B revenue) companies and large enterprises.

While the processes vary by company size, key metrics that embody the majority of costs tend to be the same.

"The industry lacked and sorely needed an independent look at what it truly costs to secure a database, from soup to nuts, as well as a guide to help practitioners better understand all of the aspects of protecting the database," said Thom VanHorn, Vice President of Marketing, AppSec. "We believe the tremendous work that Securosis put into DB Quant represents the most significant step forward in helping companies get their arms around a very complex situation in an easy to understand format. We expect this to serve as the standard database security framework moving forward."

Webinar and Report Information: AppSec will be hosting a webinar with Adrian Lane and Rich Mogull of Securosis, who will share a behind the scenes look at the creation of "DB Quant", why it was a project that they engaged in, what the content of the guide entails and how to best use the information.

Title: Measuring and Optimizing Database Security and Compliance Operations Date: Tuesday, April 26, 2011 Time: 2:00 PM - 3:00 PM EDT Register: https://www1.gotomeeting.com/register/234255137

Download a free copy of the guide: "Measuring and Optimizing Database Security and Compliance Operations: An Open Model".

About Securosis Securosis is an information security research and advisory firm dedicated to transparency, objectivity, and quality. We are totally obsessed with improving the practice of information security. Our job is to save you money and help you do your job better and faster by helping you cut through the noise and providing clear, actionable, pragmatic advice on securing your organization. For more information, please visit: www.securosis.com.

About Application Security, Inc. AppSec is the leading provider of database security, risk and compliance (SRC) solutions for the enterprise. AppSec's agentless approach - AppDetectivePro for auditors and IT advisors, and DbProtect for the enterprise - delivers the industry's most scalable database SRC solution and is in use around the world in the most demanding environments by over 2,000 customers. The company was named to Inc. Magazine's 2007 (Inc. 500) and 2008 list of America's Fastest Growing Private Companies, and was also named to the 2008 Deloitte Technology Fast 50 by Deloitte & Touche.

For more information, please visit www.appsecinc.com | www.teamshatter.com

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
FluBot Malware's Rapid Spread May Soon Hit US Phones
Kelly Sheridan, Staff Editor, Dark Reading,  4/28/2021
7 Modern-Day Cybersecurity Realities
Steve Zurier, Contributing Writer,  4/30/2021
How to Secure Employees' Home Wi-Fi Networks
Bert Kashyap, CEO and Co-Founder at SecureW2,  4/28/2021
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-05-06
An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel i...
PUBLISHED: 2021-05-06
A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbi...
PUBLISHED: 2021-05-06
aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
PUBLISHED: 2021-05-06
The administrator application on ASUS GT-AC2900 devices before allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_chec...
PUBLISHED: 2021-05-06
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.