BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Databases Need Least Privilege Too

Posted May 25, 2011    Peter McCalister

The most sensitive information assets for any size company larger or small tends to be buried inside a database sitting on a server. It doesn’t matter if that server is physical, virtual or cloud based. Some organizations choose to protect the database and some the server. The best solution would be to protect both according to their intrinsically different requirements.

We at BeyondTrust have been experts in least privilege, insider threats, privilege identity management and the implications for governance, risk and compliance for over two decades now. We’ve seen an evolution in how corporations and especially our vast customer base are looking at ways of securing the perimeter within the extended enterprise as cloud and virtual sprawl takes root.

One of the most important observations recently involves the nature of database security and the debate of whether to rely exclusively on the security tools provided by the database vendor or leverage 3rd party solutions to extend those tools risk mitigation capabilities. What we are seeing mostly is that 3rd party tools do significantly extend the security, risk mitigation and compliance value to organizations and therefore critical to any database administrator’s checklist.

In this blog we have talked extensively about the value of session management (read “logging”) in concert with policy-based brokering (read “least privilege”). This also extends to the application space, and specifically databases. Watch this blog for lots more on this subject as we think it is getting very hot again.

Leave a Reply

Additional articles

red-thumbprint

Why big data breaches won’t always be so easy

Posted September 19, 2014    Byron Acohido

This blog post is republished with the permission of ThirdCertainty. See the original post here. – By: Byron Acohido, Editor-In-Chief, ThirdCertainty Some day, perhaps fairly soon, it will be much more difficult for data thieves to pull off capers like the headline-grabbing hacks of Home Depot and Target. That’s not a pipe dream. It’s the projected outcome…

Tags:
, , , , ,
pbps-blog2

8 Reasons Your Privileged Password Management Solution Will Fail

Posted September 18, 2014    Chris Burd

Leveraging complex, frequently updated passwords is a basic security best practice for protecting privileged accounts in your organization. But if passwords are such a no-brainer, why do two out of three data breaches tie back to poor password management? The fact is that not all privileged password management strategies are created equal, so it’s critical…

Tags:
, , , , , ,
pbps-customer-campaign-image

You Change Your Oil Regularly; Why Not Your Passwords?

Posted September 11, 2014    Chris Burd

There are many things in life that get changed regularly:  your car oil, toothbrush and hopefully, your bed sheets.  It’s rare that you give these things much thought – even when you forget to change them. But what if you’re forgetting something that can cost you millions of dollars if left unchanged for long periods…

Tags:
, , ,