|
External threats are no longer the sole concern, and they may not even be the primary concern. As organizations have become increasingly complex, and leveraged technology to link core IT assets to more and more personnel throughout the organization—and even outside the organization, to business partners and customers—security strategies solely focused on the network perimeter no longer suffice. Many of today's most damaging and high-profile security breaches stem from internal security threats. In such cases, a trusted insider achieves unauthorized access to mission-critical data, and then proceeds to destroy, modify, or simply copy it. The consequences to the organization in this event can be enormous—even catastrophic—and they occur surprisingly often. Some studies suggest, in fact, that trusted insiders are responsible for up to 80% of all security breaches. Improving database security to accommodate the possibility of abuse by privileged users often breaks down into developing a number of different steps. For instance, consider the question of application access. Different applications are required for different purposes, and different users will inevitably have different levels of access and power within them. Establishing database security policies which determine different levels of access by different users, and tracking those transactions to different areas, can be a challenging proposition. Our goal is to comprehensively monitor the activity of these users, regardless of what functionality they have access to and what data they can see. In addressing this issue we ask the following questions: Ø Where are users coming from and at what time? Ø What are users doing within the system? Ø What are administrators, DBAs and root users doing on the system? Ø Were system changes authorized? Ø Was privileged access used to violate separation of duties policies? Ø Has a disgruntled administrator attempted theft? Ø Has confidential or regulated data been viewed by administrators? Enterprises need actionable insight into privileged user behavior. Sahaa Solutions provides a cost-effective, automated way to monitor, report and investigate these user behaviors to both protect information assets and confidential information.
|