Commentary

Mitch Irsfeld
 

Data Misuse Comes In Many Forms

Yesterday I issued a reminder that data security and compliance meant protecting the data stores as well as the network perimeter, but good compliance practices also require a consistent and thorough monitoring of the way your users are interacting with the enterprise applications, in particular your databases. Once again we are talking mostly about internal intruders, those getting access to information they are not authorized to use or using authorized information in an unauthorized manner. And three recent product releases could point you in the right direction or at least help you frame the issues.

Yesterday I issued a reminder that data security and compliance meant protecting the data stores as well as the network perimeter, but good compliance practices also require a consistent and thorough monitoring of the way your users are interacting with the enterprise applications, in particular your databases.

Once again we are talking mostly about internal intruders, those getting access to information they are not authorized to use or using authorized information in an unauthorized manner.


More Global CIO Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

And three recent product releases could point you in the right direction or at least help you frame the issues.First we note that Embarcadero Technologies Inc's recent acquisition of database-security software maker SHC Ambeo Acquisition Corp. has yielded database-monitoring software in the form of Ambeo's Activity Tracker, a database-auditing mechanism that monitors all user activity in real time, and Usage Tracker, which provides historical statistics on how data is being accessed and used.

Similarly, Consul Risk Management Inc. brought out version 6.0 of its flagship InSight Suite that helps administrators analyze user and system activity and report on who touched what information and how those actions may violate external regulations or internal security policies.

And earlier this week Tizor unveiled its Mantra activity-auditing appliance. Mantra monitors what individual users are doing with mission critical applications and data by using analytics capabilities such as behavioral fingerprinting, which detects patterns in user activity that could signal malicious activity.

What each of these monitoring systems has in common is the focus on user activity rather than simply checking access rights. You may have policies governing the use of corporate databases, but no matter how well defined the policies, if you lack visibility into the usage patterns, you lack the controls required under several regulations, including SOX and HIPAA.

And the usage behavior doesn't have to be malicious to be non-compliant. The ability to flag and investigate abnormal data use, no matter how inadvertent, is just as important as catching those with bad intent.

When it comes time to attest to your internal controls, how your data is used can reveal just as much as who is using it.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links