• Skip Navigation |
  • Accessibility 
Sustainable Manufacturing Summit (19-21 Nov, Belgium)
IT-Director.com Logo
  • What is Symantec's vision?
  • MarketSight 7.0 - Survey Analysis Made Simple
  • Learning from the credit crunch to avoid a broadband crunch
 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • RESEARCH
  • EVENTS
  • NEWSWIRE
  • BLOGS
  • POLLS

  

Member Login | Become a Member

 
DOMAINS
  • Enterprise
  • SME
  • Business Issues
  • Technology
  • Services
  • Channels
FEATURED EVENTS
  • PLM North America 2008
    13th October - 15th October
    St Augustine, USA
  • Storage Expo 2008
    15th October - 16th October
    London, United Kingdom
POPULAR PAPERS
  • Keep Talking Not Spending by Quocirca
  • Remote IT Management by Quocirca
  • We are all IT users now by Quocirca
TRANSLATE PAGE



USEFUL LINKS
  • Last 7 Days
  • Archives
  • Market Place
  • Top Articles
  • Hall of Flame
INTERACT
  • Advertising
  • About IT-Director.com
  • Site Feedback
  • Newsletters
  • Contact Us
  • Registration
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Famous Slights - "He is a man of splendid abilities but utterly corrupt. He shines and stinks like rotten mackerel by moonlight." - John Randolph

ADVERTISEMENT
Blogs > Nigel Stanley

InfoSec Show or DataSec Show?

Nigel Stanley By: Nigel Stanley, Practice Leader - IT Security, Bloor Research
Published: 26th April 2007
Copyright Bloor Research © 2007
Logo for Bloor Research
Page Tools

Request Reprints
Tell A Friend
Contact Author

Recent Blog Posts
  • PGP and IBM Supporting Bletchley Park
  • The importance of saving Bletchley Park
  • The real cost of data loss is down to butterflies
  • Glengarry Glen Ross - Old Fashioned Inside Threat
  • Symantec Spammers Rock 'n' Roll
  • Crap Government IT Rules OK? Oh well, pass the biscuits.
Blog Archive
  • September, 2008
  • July, 2008
  • March, 2008
  • January, 2008
  • December, 2007
  • November, 2007
  • October, 2007
  • September, 2007
  • July, 2007
  • May, 2007
  • April, 2007
  • January, 2007
Syndication
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon

Maybe InfoSec should be rechristened the database security show?

There appear to be more and more vendors now focussed on securing the good old database by offering tools that layer onto an existing RDBMS, monitoring who is doing what and when and then taking, if needed, appropriate action.

A interesting player in the market for enhanced data security is Protegrity (www.protegrity.com). The nature of retail can be an IT security nightmare from the start. We have high turnover of shop staff that have access to customer credit card details, we have shoppers placing orders via telesales and then we have the really wild ecommerce environment when anything goes. By wrapping technical smarts around virtually any database platform, including AS400, Oracle, SQL Server and TerraData, Protegrity are able to offer clients a high degree of security along with a useful reporting mechanism.

Of course the reporting mechanism is vital. What point is there in having good security if the CSO/CIO or any other CXO can’t have a nice big smiley face on their portal to assure them that “all is well”?

Meanwhile PGP (www.pgp.com) are busily encrypting anything that will move, on the basis that even if a laptop does go missing if the data is encrypted it will have little value beyond the £25 the local smackhead got for it in the pub.

By the way, although we will all report loss or theft of our laptops, how many would do the same for a USB key? In fact ask yourself the question – how many USB sticks have you lost? Scary when you think about it.

According to research carried out by PGP working with the Ponemon Institute reputational risk is now a big worry for many organisations, so mitigating this with decent encryption is a no brainer for many. I’ll try and share more of this research at another time.

ActivIdentity (www.actividentity.com) meanwhile are working hard to bring together the world of physical security with logical security. With their access card systems they can build scalable, manageable card access systems to control door access alongside computer access. Interestingly they are seeing the coming together of some facility management responsibilities under the umbrella of the CTO or other security manager. This isn’t to say that the CTO is now known as the Cleaning the Toilet Officer, rather they are assuming responsibility for managing physical security assets that maybe was not part of their portfolio before.

Hey, it makes sense to me.

McAfee (www.mcafee.com) are busy extending their portfolio of products by aggressive acquisition, development and enhancement. They now have an interesting suite of products that starts to deliver on this vision we have all been clamouring for – single management of all my security estate. Tough gig, but if they can crack it then good luck to them.

One aspect of InfoSec I really enjoy is dodging the vendors that like to thrust a gamut of DVDs and paperwork in your hand as you rush by to yet another briefing. I normally manage to avoid collecting too much (especially since I have just come back from Egypt, and escaping the street sales people became a fine art) but for once I was actually caught.

So there you have it, another day at DataSec.

Let’s see what day 3 brings.

Reader Comments

We are no longer accepting comments against this item. We suggest contacting the author directly.

  • Site Map
  • | Terms of Use
  • | Privacy

Published by: IT Analysis Communications Ltd.
T: +44 (0)203 051 5760 | F: +44 (0)870 345 9922