This is an interesting question, particularly when organizations are driven by regulatory compliance requirements,...
By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers.
such as Gramm-Leach-Bliley, HIPAA, and SOX, to demand more advanced security features to protect their most valuable assets -- their data. Database Management Systems (DBMS) can differ greatly. They range from small membership lists that run on personal computers to systems that run on mainframes, such as flight reservation systems. Before I talk about what you should expect to see from DBMS vendors, I will quickly review what protection is pertinent to a DBMS. Comprehensive DBMS security requires an end-to-end approach. It encompasses encryption, security assessment and auditing, intrusion detection and prevention, and is supported by policies and procedures that will minimize the risk and impact of malicious attacks. Databases also need support from proper backup protection and patch management procedures. Network-based applications should use data encryption for sensitive data both at rest and in transit, while protected by a network architecture that provides defense-in-depth.
Although Oracle continues to lead database security solutions, many DBMS products only offer basic security features and do not provide the capability to harden the database environment. Most advanced security functions are provided by smaller, specialized vendors, who focus on addressing functional gaps. To achieve comprehensive DBMS security, you should look at a combination of products. A good starting point is Application Security's product suite atwww.appsecinc.com, which, according to Forrester Research, offers the most comprehensive database security solution, covering data-at-rest encryption, assessment, auditing, and intrusion detection and prevention.
Looking ahead, as DBMS vendors add new security features and the specialized DBMS security vendors continue to set the pace, innovations in DBMS security will make it worthwhile to keep abreast of the developments.
Dig Deeper on Database Security Management-Enterprise Data Protection
Related Q&A from Michael Cobb
Geofencing technology is increasingly being used as a security tactic, such as to control access to servers with DNS settings. Expert Michael Cobb ...continue reading
After a remote code execution flaw in PHPMailer was patched, the problem persisted, and had to be repatched. Expert Michael Cobb explains how the ...continue reading
The same-origin security feature in Adobe Flash Player was implemented incorrectly, allowing local attackers to spy on users. Expert Michael Cobb ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.