Blog|Login|中文Deutsche日本語
July 31, 2012
 Database security: At rest, but not at risk
Pin It

At Black Hat, former FBI agent Shawn Henry spoke on a new security paradigm which was based on the idea that "It is not enough to watch the perimeter."  Almost exactly a year ago, we outlined how one of our customers uses database controls to mitigate spear phishing since they assume, as Mr. Henry does, that a compromise has taken place.

Today, IDG published a great article on database security that underscores why perimeter security isn't enough:

Database security is starting to show up on the radar of C-level execs, and no wonder. According to Verizon's "2012 Data Breach Investigations Report," 174 million corporate records were compromised in 2011 (the highest since 2004, according to the company), and in a survey by the Independent Oracle Users Group, 31 percent of respondents anticipated a major data breach this year.

The article provides several real-world anecdotes on securing databases, including this one:

Richard Isenberg, Fiserv's VP of security engineering, turned to Imperva for tools to handle segregation of duties, vulnerability scanning and blocking suspicious activity. "The databases themselves don't have enough security baked in to meet our compliance initiatives around tracking and understanding everything that privileged users do and alert us when they're doing something we don't want," he says.

 

 


Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

« Confessions of Commercial WAF Vendor | Main | Hacktivists Breach French E-Commerce Site »

Find Us Online
RSS Feed - Subscribe Twitter Facebook iTunes LinkedIn YouTube
Authors
Monthly Archives
Email Subscription
Sign up here to receive our blog: