Question

Database security is crucial, and it is part of every business continuity plan. List at least...

Database security is crucial, and it is part of every business continuity plan. List at least two elements of a database security plan that you think are the most important and explain why. As a reference, review this article addressing Dixon Carphone (Links to an external site.), a British retailer that faced a serious breach when 1.2 million customers’ personal information from its database was compromised.

0 0
Add a comment Improve this question Transcribed image text
Answer #1

1.    Compliance: Monitoring and auditing

Compliance is an important part of a database protection solution. This is because many of the regulations and statutes provided for with compliance address very real problems faced by enterprises and to which must receive due attention.

It is an essential part of implementing IT security, but it falls short in that much of the regulations provided focus more on monitoring procedures as opposed to real-time prevention of threats to the database and system. As such, while essential, compliance is not nearly enough.

A major component of compliance is implementation of Database Activity Monitoring (DAM). The DAM will identify every activity in the database, generating reports and necessary alerts about those activities.

Compliance for each organization involves adherence to relevant standards bodies’ regulations e.g. the SOX, PCI-DSS or HIPAA, as well as any relevant international compliance standards e.g. ISO 27001 standard on Information Security Management Systems.

By applying DAM, you will be able to tell who is accessing the database (individual or entity) and why. Most standards bodies require a comprehensive reporting system outlining who or what did what, when and why.

Every database protection solution must therefore include tools that detect and alert the relevant admins about activities that deviate from the standard policies (organizational and otherwise) or are suspicious. Having alerts for suspicious behaviors will help you to manage such issues in real-time, even if you have a DB firewall.

Monitoring should also include sins of omission i.e. what needs to be done but has not been. Examples include regular changing of passwords or monitoring individuals that have DB privileges that they have not ever used. Information on lack of activity will help you know where there is proffering of excessive privileges so that you can revoke them before they are misused.

2.    Separation of tasks and access control

Access control primarily aims at preventing malicious attacks and potential threats from within the organization. While there are instances of deliberate malicious attacks from insiders, more often than not these result from theft of login credentials.

By separating duties and assigning functionality and privileges according to user requirements, you can limit the extent of damage in case of potential or actualized threats. For instance, a user responsible for creating backup files to the DB needs never see the actual content in the DB. A tester will need access into the database, but not necessarily to actual data stored therein.

In duty separation, you must give every user only the minimum access needed to carry out the job. By allowing every user to only carry out tasks under their jurisdiction you can largely protect your databases from inadvertent as well as deliberate breaches.

Every DB protection tool or solution must include functions for separation of tasks, with as large a range as possible of controls and privilege regulation. Apart from the inbuilt tools, the database firewall should be able to detect what users are in the system, allowing even greater control over their privileges and applications within the database.

Add a comment
Know the answer?
Add Answer to:
Database security is crucial, and it is part of every business continuity plan. List at least...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • The discussion: 150 -200 words. Auditing We know that computer security audits are important in business....

    The discussion: 150 -200 words. Auditing We know that computer security audits are important in business. However, let’s think about the types of audits that need to be performed and the frequency of these audits. Create a timeline that occurs during the fiscal year of audits that should occur and “who” should conduct the audits? Are they internal individuals, system administrators, internal accountants, external accountants, or others? Let me start you: (my timeline is wrong but you should use some...

  • TASK Read the Regional gardens case study document before attempting this assignment. Background: You have been...

    TASK Read the Regional gardens case study document before attempting this assignment. Background: You have been employed by Regional Gardens as their first Chief Information Officer (CIO). You have been tasked by the Board to conduct a review of the company’s risks and start to deploy security policies to protect their data and resources. You are concerned that the company has no existing contingency plans in case of a disaster. The Board indicated that some of their basic requirements for...

  • Please need serious and professional help! Hello! I am working on an "object oriented analysis and...

    Please need serious and professional help! Hello! I am working on an "object oriented analysis and design" Project. I would really need your sincere help in creating a vision document for this project. The Things That I require in the "vision document" is: 1. Product Overview [This section provides a high level view of the product capabilities, interfaces to other applications, and system configurations. This section usually consists of three subsections, as follows: •          Product perspective •          Product functions •         ...

  • CASE 17: WATSON’S AMBULATORY EHR TRANSITION Major theme: System acquisition Primary care physicians play a key...

    CASE 17: WATSON’S AMBULATORY EHR TRANSITION Major theme: System acquisition Primary care physicians play a key role in the U.S. health care delivery system. These providers integrate internal and external information with their clinical knowledge to determine the patient’s treatment options. An effective ambulatory electronic health record (EHR) is critical to supply physicians with the information they need to provide quality care and maximize their efficiency. This case involves the decision-making process to replace an inadequate EHR system in a...

  • 1.2 Recruitment is one of the crucial functions of HRM. Based on the information provided below,...

    1.2 Recruitment is one of the crucial functions of HRM. Based on the information provided below, how would you describe THE COMPANY’s approach to recruitment, before and after the implementation of the Brand Ambassador Program? How did the use of social media lead to the revision of the whole approach regarding recruitment? How ‘THE COMPANY’ Developed a Brand Ambassador Program At ‘THE COMPANY’ we usually categorize Employment Brand at ‘THE COMPANY’ into four big ‘buckets’: candidate experience, brand ambassador programs,...

  • Discussion questions 1. What is the link between internal marketing and service quality in the ai...

    Discussion questions 1. What is the link between internal marketing and service quality in the airline industry? 2. What internal marketing programmes could British Airways put into place to avoid further internal unrest? What potential is there to extend auch programmes to external partners? 3. What challenges may BA face in implementing an internal marketing programme to deliver value to its customers? (1981)ǐn the context ofbank marketing ths theme has bon pururd by other, nashri oriented towards the identification of...

  • 1. find an article about a product or service that impacts your daily life and write...

    1. find an article about a product or service that impacts your daily life and write 1 to 2 paragraphs describing the item, how it impacts your life, and what factors you think are impacting the supply and demand of this item. Be sure to include the URL of the article you accessed for this question. 2.What are the ethics of outsourcing? Is a corporation’s primary responsibility to its stockholders, by reducing labor costs? Or is its primary responsibility to...

  • Please read the article and answer about questions. You and the Law Business and law are...

    Please read the article and answer about questions. You and the Law Business and law are inseparable. For B-Money, the two predictably merged when he was negotiat- ing a deal for his tracks. At other times, the merger is unpredictable, like when your business faces an unexpected auto accident, product recall, or government regulation change. In either type of situation, when business owners know the law, they can better protect themselves and sometimes even avoid the problems completely. This chapter...

  • I have this case study to solve. i want to ask which type of case study...

    I have this case study to solve. i want to ask which type of case study in this like problem, evaluation or decision? if its decision then what are the criterias and all? Stardust Petroleum Sendirian Berhad: how to inculcate the pro-active safety culture? Farzana Quoquab, Nomahaza Mahadi, Taram Satiraksa Wan Abdullah and Jihad Mohammad Coming together is a beginning; keeping together is progress; working together is success. - Henry Ford The beginning Stardust was established in 2013 as a...

  • Case: Enron: Questionable Accounting Leads to CollapseIntroductionOnce upon a time, there was a gleaming...

    Case: Enron: Questionable Accounting Leads to CollapseIntroductionOnce upon a time, there was a gleaming office tower in Houston, Texas. In front of that gleaming tower was a giant “E,” slowly revolving, flashing in the hot Texas sun. But in 2001, the Enron Corporation, which once ranked among the top Fortune 500 companies, would collapse under a mountain of debt that had been concealed through a complex scheme of off-balance-sheet partnerships. Forced to declare bankruptcy, the energy firm laid off 4,000...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT