Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

6/11/2009
05:00 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Report: No Magic Bullet For Database, Server Security

New Forrester report says encryption, data monitoring technologies key tools for now

There's no quick fix for securing data on databases and servers, and new tools that can prevent attacks on these systems are a long way off, according to a new report.

For the near term, encryption will remain the most popular defense for locking down data on databases and servers, while database monitoring and Web filtering will continue to be pervasive tools for breach detection, according to Forrester Research's new report.

Protecting data on servers and databases has never been easy, and doing so has become only more challenging with mobile users, cloud computing, and an unstable employment climate, says Jonathan Penn, vice president of tech industry strategy/security at Forrester, who co-authored the report with Forrester's Andrew Jaquith. "Over the foreseeable planning horizon, help for CISOs will not arrive in the form of a miracle tonic. Forrester does not foresee that a miraculous technology -- for example, error-free data discovery and classification -- will emerge to save the day," he says.

Instead, existing "brute force" tools, like encryption and data masking, will continue to emerge as the key tools to keeping data under wraps, while database monitoring and Web application filtering will provide insight into breaches. "While prevention may not prove practical in all cases, detection will be," Penn says. Compliance and contractual requirements will keep organizations buying those technologies, which "give them visibility to theft, corruption, and abuse as it happens," he adds.

The Payment Card Industry Data Security Standard (PCI DSS) and states' data breach disclosure laws are driving enterprises to adopt these data security technologies.

Meanwhile, enterprises aren't ready to deploy data discovery and classification technologies, Forrester says. The data discovery market won't mature for several years, Forrester says, even though the concept of crawling an enterprise network to find where the sensitive data lives should be a no-brainer by now in this age of big search engines.

Data classification, meanwhile, won't hit its stride until about 2014, when security-specific data classification tools will blend with knowledge management and electronic records classification technologies.

"Classification is a challenge because many different groups are looking at [it] from different perspectives and not coordinating their efforts," Penn says. The security, storage management, legal departments, and information/knowledge management groups all need these tools, but they won't make it into the organization until security/risk management and information/knowledge management team, he says.

"These groups will realize that by aligning their interests, they can be more effective, consolidate vendors, and cut costs," Penn says.

Plus, data classification tools, such as data protection, archiving/retention, e-discovery, and knowledge management, are very focused, he says. "For example, e-discovery classification tools have far less sophistication in their content analysis capabilities than the DLP [data leakage protection] tools security people are employing," he says. "Classification needs to be done in the infrastructure, across areas, so that a file managed by the archive system is classified the same way that a rights management [system] would classify it when deciding who can look at it, and the same way a DLP product would classify it when deciding whether a user can send it off to a USB or by email."

Forrester's report, "TechRadar For Vendor Strategy Professionals: Database And Server Data Security, Q2 2009," is geared for vendors looking at how to plan their strategies in this space.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/17/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Meet the Computer Scientist Who Helped Push for Paper Ballots
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5421
PUBLISHED: 2020-09-19
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
CVE-2020-8225
PUBLISHED: 2020-09-18
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.
CVE-2020-8237
PUBLISHED: 2020-09-18
Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.
CVE-2020-8245
PUBLISHED: 2020-09-18
Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11....
CVE-2020-8246
PUBLISHED: 2020-09-18
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-W...