| Watch out! Is your DBA a spy? |
|
|
|
| Monday, 30 October 2006 | |||||
|
These data, actually represent a huge threat for companies, because according to Jerald Murphy, senior vice president and director of research operations at The Robert Frances Group, the risk that people could do illegitimate things with data they have legitimate access to is much less well container. "Consequently, this is one of the greatest sources of data security vulnerability -- and one of the hardest to defend against -- that organizations face today." Considering that a DBA, a Data Base administrator, works with database management systems software and determine ways to organize and store any kind of sensitive data, he or she could make a perfect spy copying and using for malicious purposes both corporate secrets and employee or customer personal information. A simple negligence could be enough to create a big loss to the company, even if not purposeful: an employee with regular access to data bases could download some information on a laptop and carry it in a business trip.. what if the lap top were stolen, or forgotten and consequently data were exposed? It isn’t easy to detect such frauds, especially those provoked by internal elements, but now software is available which can help guard data from internal threats. Mr Murphy suggests to encrypt most sensitive data, to pay constant attention to DBAs movements and to review log files for suspicious activities. "If a DBA is doing a lot of seeks at 11 p.m., for instance, I have to wonder what he is doing."Encryption seems to be the best solution according to him, indeed he recommends using third-party encryption utilities from vendors such as Protegrity or Ingrian Networks because if the encryption is done by the database engine, the DBA has access to the key, and if the DBA is stealing the data, this will not stop him. Then, on the other hand, the keys will be stored in the database, and if they become corrupted, data recovery will be difficult. “Third-party encryption removes the keys from the DBA's purview, allowing the separation of responsibilities between database management and security. These third-party solutions keep the keys outside the database and have sophisticated key management, making recovery simpler should the keys become corrupted.” Another important step would be to adopt Extrusion solutions that would intercept sensitive data on its way out of the corporate network and preventing it from crossing the corporate boundaries and notifying a designated individual, such as the corporate security officer. Among the available programs, experts suggest Vontu for e-mail, including attachments and Fidelis Security Systems to encompass all files. "This is the opposite of a firewall, and it is important for catching the mistakes of well-meaning employees that are behind 80% of corporate data security breaches." "Best practice is to look at the total life cycle of the data -- who creates it, where it is stored, who uses it and how it is used," says Murphy. "The reality is there is no silver bullet for data protection. It is one thing to expect IT professionals to adhere to good data protection and quite another to try to get every end-user to line up behind security policy.”Security is one of the most important aspects in a company, and there’s no justification for any leak. We know it, we reported it and we have been repeating it many, many times… but we are not sure that these would be effective solutions. First of all because sometimes data HAVE to be sent outside the virtual borders of a company for legitimate reasons, and then because we don’t think that checking emails and controlling the logs could be a precise indicator that something is going wrong, because how many people keeps working until late in certain periods? Are all of them potential spies? The truth is that we are all potential spies and companies have to undertake countermeasures to protect themselves, and the border line between defending a company’s right of protection and breaking people’s right for privacy is really very thin.
Powered by a Zone-H(ified) version of AkoComment 3.0! DISCLAIMER: Forum postings are the opinion of the posting author alone, and should not be taken as the opinion of Zone-h. The author is entirely and solely responsible for all content that he/she uploads, posts, or otherwise transmits via the website. Zone-h is not responsible for such content. However, Zone-h shall have the right, but not the obligation, to delete, move, or edit any content that violates this agreement or is otherwise objectionable as determined by Zone-h in its sole discretion and without notice. |
|||||
| < Prev | Next > |
|---|









The 80% of data breaches are provoked by external attacks but this means that in 20 cases on 100, there’s the risk that the leak have been caused by an employee of the affected company, 

