October 12, 2008   Sign In |  About ebizQ |  Contact Us |  Join ebizQ Gold Club
Security Syndicate This
Print this article    Email this article    Talk Back!    Write to Editor
Database Security: A Shifting Landscape
08/10/2006
By David A. Kelly, Analyst, ebizQ

Protecting your corporate data takes more than simply securing your network or locking down your database. With a range of security issues facing organizations today, ensuring adequate data security requires a holistic and broad security strategy that goes beyond traditional, technically-focused AAA procedures (authentication, authorization and access control). Especially in light of new regulatory and compliance drivers like Sarbanes-Oxley or Gramm-Leach-Bliley.

ADVERTISEMENT
Our Popular Webinars
The Smart SOA™ approach to governing WebSphere MQ Applications with IBM WebSphere Service Registry and Repository
BPM for Insurance: Are You Staying Competitive?
Enterprise Service Bus: The case for 'e'SBs
Know Thy Enterprise: Increase Effectiveness With Business Activity Monitoring (BAM)
How Secure is Your Data? Learn about PCI Solutions
You Can Implement Today.
More Webinars

Of course, an organization’s data is a critical component of an appropriate security strategy. But it’s not just the protection of data that’s important these days, but the integrity of data—everything from the data in the databases to the data in the system logs to even the data that resides in non-relational systems. This aspect of integrity becomes even more important when faced with compliance requirements. When an auditor is examining the integrity of the financials, the trail pretty quickly leads back to the systems of record and the underlying databases—not only what’s in them, but who had access to them when and who might have changed what.

For the past few years, a lot of focus in the security area has been on confidentiality and the security of data, especially with regulations like HIPAA that require organizations to provide greater control over the confidentiality of specific personal data. But as we’re exploring here, it’s not just confidentiality that’s important—data integrity is also critical for ensuring an appropriate (and auditable!) data security strategy.

For example, a primary concern of auditors (and of vigilant IT managers) is the possibility that authorized users (say, database DBAs) typically have access not just to the database architecture and database settings, but to the data itself. What’s to stop a database administrator from copying off a bunch of phone numbers or credit card numbers or other corporate data?

One approach to solving this type of data access by privileged users problem is to encrypt the data to prevent the DBA from ever being able to do that, since the encryption keys for that data could be held by another person. Such a solution would require that the DBA plus the other person would have to work together to obtain access to that data, providing some additional assurance on top of traditional approaches.

Alternatively, some database vendors, such as Oracle, are offering additional data protection in the form of database realms. Database realms are essentially like areas of the database that can be surrounded and locked down without the typical overhead of the encryption requirements found in the first solution. Oracle’s Database Vault gives organizations a way to restrict access to super users (DBAs and privelaged users) via the definition of realm (or database territory) and a set of appropriate rules and conditions. For example, a database realm could be defined that would only allow DBAs to access or change database settings or content from specific IP addresses (preventing any changes from external sources, for instance), or only between certain hours (say between 9am and 5pm Monday through Friday). In effect, these database realms provide organizations with more granular access over the control of who can see what in a database, who can change what in the database, and when and where those changes can be made.

Page 1

More Top Stories
BPM Goes Wide and Deep in Insurance Gold Club Protected
Identity Networking: Where Security and Compliance Meet Gold Club Protected
Application Servers in Emerging Service Oriented Architectures Gold Club Protected
OSS: Talking to... Ilan Sehayek of Jitterbit Gold Club Protected
Secrets of SOA Standardization Success Gold Club Protected
Do You Need BPM for SOA Governance? Gold Club Protected
More Top Stories
Related News
Gartner Reveals Nine Fatal Flaws in Business Intelligence Implementations
Report: Web, XML Will Drive Business Process Management Growth
IBM Helps ACI Worldwide Unify Communications and Integrate Workforce
More News
Subscribe to our Newsletters
ebizQ Weekly Gold Club Update
Live Webinar Updates
Updates from ebizQ Partners
ebizQ SOA Update
ebizQ BPM Update
ebizQ Security Update
ebizQ BI Update
ebizQ Open Source Software Update
Virtual Show Newsletter
ebizQ Web 2.0 and the Enterprise
Your E-mail Address:
Enterprise Service Bus: The case for 'e'SBs
Date: Oct 16, 2008
Time: 14:00 PM ET
(18:00 GMT)

REGISTER TODAY!
BPM for Insurance: Are You Staying Competitive?
Date: Oct 28, 2008
Time: 12:00 PM ET
(16:00 GMT)

REGISTER TODAY!
Archived Webinars | Upcoming Webinars
  Integrated SOA Governance

Many large organizations are reducing...Learn More

ebizQ also recommends
 FILLING HOLES IN THE SOA STACK WITH RUNTIME GOVERNANCE
 SOA Middleware: An Agile Framework for Fast, Flexible, Low-Risk Service Deployments
 Multi-Enterprise Integration and Managed File Transfer
 How to Structure your First BPM Project to Avoid Disaster
 How Social Computing, Team Collaboration, and Enterprise Content Management Drive Competitive Advantage
More White Papers

Marketing Solutions | Feedback | About ebizQ | Unsubscribe | Privacy Policy | Site Map

Live Chat