That Sinking Feeling - Information Security Magazine - Page 1

Before you lose something precious, govern your data.


Your company doesn't have to fall victim to a sinister SQL injection attack for its sensitive corporate or customer information to come pouring out of a database. Shoddy data governance can do as much to poke a hole in a data store as sloppy data input validation.

It's the CISO's job to balance the business need that data be available and shared with partners, suppliers and customers, while putting controls in place to fend off trusted insiders and malicious outsiders--and appease auditors. All the while, data grows in near immeasurable volumes and is accessible via many avenues on the Internet and corporate extranets. Adding to the stress is the often routine practice of replicating databases for backup, high availability and--too often--for development. Their content is accessed and stored by myriad applications, partners and customers, sometimes in ways you don't appreciate or even suspect.

In short, data lives everywhere, and security constantly tries to keep up with a moving target.

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

More information from SearchSecurity.com

Check out Bitpipe's database security whitepaper library.

Whether your company is built on a strong foundation of data governance and intelligent risk management, or has been forced to "do something" because of PCI, Sarbanes-Oxley, HIPAA, SB 1386 or other regulatory mandates, it's obvious that the cost of weak data security is greater than the implementation of strong controls. Here are the top database security challenges facing corporations today, and guidance on how to meet them.

This was first published in October 2006