Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

4/13/2011
01:10 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

AppSec And Securosis Team Up To Provide Comprehensive Guide For Database Security Programs

Guide provides insight into all common database security tasks

NEW YORK and PHOENIX - April 12, 2011 - Application Security, Inc. (AppSec), the leading provider of database security, risk and compliance solutions (SRC) for the enterprise and independent research and analysis firm Securosis, today announced the availability of the industry’s first comprehensive guide to quantifying enterprise database security processes.

Sponsored by AppSec and independently researched and written by Adrian Lane, analyst and CTO and Rich Mogull, analyst and CEO of Securosis, the guide to securing databases is titled, "Measuring and Optimizing Database Security and Compliance Operations: An Open Model". Dubbed by Securosis as "DB Quant" (short for Database Security Quant Research Project), the guide provides insight into all common database security tasks, with the goal of equipping organizations with a tool to better understand the security costs of configuring, monitoring and managing databases.

"Despite being the most important repositories for the most sensitive and critical data, the ongoing, multi-year spate of data breaches proves that most organizations still struggle to effectively secure databases," said Rich Mogull. "So when AppSec pointed out the need for an independent model for measuring the costs of database security, we were excited about creating what we believe has become the first totally objective, comprehensive database security program framework."

"Database security encompasses a large number of processes managed by different teams -- from database administrators (DBAs), to security operations, to IT operations, really running the gamut of operational staff," said Adrian Lane. "Our research has uncovered a consistent set of processes every IT team goes through to secure their databases, and each has a quantifiable cost associated with it. Thus with DB Quant, organizations can now model their database security program, in terms of costs and effectiveness."

With this in mind, DB Quant contains six major phases, with 21 sub-processes and dozens of operational metrics presented in an 80-page guide. The highlights are also available in an Executive Summary packaging, hitting the highlights of the process. Some of the key findings of the 18-month long research project include:

At the time this project started, there were no standardized processes for database security in the industry.

Staff time for setup tasks and policy management represents the majority of costs.

Auditors and operations management personnel - responsible for regulatory mandates and industry compliance - followed the same set of security processes.

There is a great divide in the depth and complexity of the processes used by mid-market (less than $1B revenue) companies and large enterprises.

While the processes vary by company size, key metrics that embody the majority of costs tend to be the same.

"The industry lacked and sorely needed an independent look at what it truly costs to secure a database, from soup to nuts, as well as a guide to help practitioners better understand all of the aspects of protecting the database," said Thom VanHorn, Vice President of Marketing, AppSec. "We believe the tremendous work that Securosis put into DB Quant represents the most significant step forward in helping companies get their arms around a very complex situation in an easy to understand format. We expect this to serve as the standard database security framework moving forward."

Webinar and Report Information: AppSec will be hosting a webinar with Adrian Lane and Rich Mogull of Securosis, who will share a behind the scenes look at the creation of "DB Quant", why it was a project that they engaged in, what the content of the guide entails and how to best use the information.

Title: Measuring and Optimizing Database Security and Compliance Operations Date: Tuesday, April 26, 2011 Time: 2:00 PM - 3:00 PM EDT Register: https://www1.gotomeeting.com/register/234255137

Download a free copy of the guide: "Measuring and Optimizing Database Security and Compliance Operations: An Open Model".

About Securosis Securosis is an information security research and advisory firm dedicated to transparency, objectivity, and quality. We are totally obsessed with improving the practice of information security. Our job is to save you money and help you do your job better and faster by helping you cut through the noise and providing clear, actionable, pragmatic advice on securing your organization. For more information, please visit: www.securosis.com.

About Application Security, Inc. AppSec is the leading provider of database security, risk and compliance (SRC) solutions for the enterprise. AppSec's agentless approach - AppDetectivePro for auditors and IT advisors, and DbProtect for the enterprise - delivers the industry's most scalable database SRC solution and is in use around the world in the most demanding environments by over 2,000 customers. The company was named to Inc. Magazine's 2007 (Inc. 500) and 2008 list of America's Fastest Growing Private Companies, and was also named to the 2008 Deloitte Technology Fast 50 by Deloitte & Touche.

For more information, please visit www.appsecinc.com | www.teamshatter.com

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Commentary
Ransomware Is Not the Problem
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  6/9/2021
Edge-DRsplash-11-edge-ask-the-experts
How Can I Test the Security of My Home-Office Employees' Routers?
John Bock, Senior Research Scientist,  6/7/2021
News
New Ransomware Group Claiming Connection to REvil Gang Surfaces
Jai Vijayan, Contributing Writer,  6/10/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-24376
PUBLISHED: 2021-06-21
The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload a zip which contained a directory w...
CVE-2021-24377
PUBLISHED: 2021-06-21
The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the file is extracted on t...
CVE-2021-24378
PUBLISHED: 2021-06-21
The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded via the 'Import Settings' feature. As a result, it is possible for a high privilege user to upload a malicious file containing JavaScript code inside an archive which will execute w...
CVE-2021-24379
PUBLISHED: 2021-06-21
The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not prevent them from replaying the AJAX request to add a like. This allows any user (even unauthenticated) to add unlimited like/dislike to any comment. The plugin appears to have some...
CVE-2021-24383
PUBLISHED: 2021-06-21
The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue