Database Securitys Biggest Problem: People

  /     /     /  
Publicated : 22/11/2024   Category : security


Database Securitys Biggest Problem: People


Many database security projects arrive DOA because database administrators and security pros arent singing the same tune.



As more organizations act to protect data at its most fundamental state, within the database, one of the biggest challenges that they run into is a people problem. In order to truly mitigate data risks, security teams need to learn to not only play nice with their database administrators, but to make them meaningful stakeholders in securing the databases theyre entrusted to manage. That takes education, respectful conversations, and a willingness from both parties to open their minds a bit, experts say.
Theres a shift going on where [as an industry] were changing our database security practices and were starting to focus on that lost realm of the database security, said Josh Shaul, CTO of Application Security. The folks who own that database, the database administrators (DBAs), are finding their worlds changing in a significant way, and some of the freedoms that theyve had are being taken away from them in order to do the security stuff. From my experience, Ive seen that dynamic really create a gap in understanding or perspective between the DBA and security team that often has led organizations to get stuck in the muck around the area of database security.
The perception gap stems largely from a divergence in technology backgrounds.
Often the DBAs focus is on performance and tuning and often many of them havent been trained on security. They do their best and theyre trying to learn it on the fly, said Scott Laliberte, managing director at Protiviti. On the flipside, a lot of the security professionals out there do not have good database skills. They tend to be operating system, network, and application folks, and you can get security folks providing recommendations that arent real practical or can introduce a problem within the database. The DBAs, therefore, fight them very hard.
According to Larry Whiteside, CISO for Visiting Nurse Service of New York, the way a lot of security controls work necessarily require some form of performance overhead within the database. It is only natural for the kneejerk reaction from DBAs to be somewhat negative.
Read the rest of this article on
Dark Reading
.
Role-based access control based on least user privilege is one of the most effective ways to prevent the compromise of corporate data. Our new report explains why proper provisioning is a growing challenging, due to the proliferation of big data, NoSQL databases, and cloud-based data storage.
Download the report now
. (Free registration required.)

Last News

▸ Sony, XBox Targeted by DDoS Attacks, Hacktivist Threats ◂
Discovered: 23/12/2024
Category: security

▸ There are plenty of online tools for reporting bugs. ◂
Discovered: 23/12/2024
Category: security

▸ 27 Million South Koreans Hit by Online Gaming Theft. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Database Securitys Biggest Problem: People