Objective: Explore automated tool that aids in database security auditing. State
ID: 3822504 • Letter: O
Question
Objective: Explore automated tool that aids in database security auditing.
Statement: Us the materials covered in chapter 9 (Security Auditing) and the Interent to find one automated tool that aides in database security auditing. Write an essay comprises summary of your finding including but not limited to the tool:
-name
-Discerption Advantages and disadvantages
-Cost
-Your recommendation about this tool this including a justification statement for using it or not
-(It is NOT recommended to install the tool).
Explanation / Answer
Name of Tool: DbProtect
This tool is a database security auditing software which helps with the activity monitoring in the databases, vulnerability assessments and prevents data breaches. It can lock block and terminate functions immediately as quick as malicious activity is detected.
DbProtect scans through all the vulnerabilities found in the databases, configuration errors or installation and access issues.
Advantages:
Support for all major database platforms.
Automated Scans for large environment
Database vulnerability remediation scripts are available.
Reporting feature for the tool will give a pictorial/graphical representation of vulnerabilities, threats and compliance across the database environment.
Reports can be schedule and emailed automatically as required by the appropriate personnel.
Identifies the privileged users and saves time by automating the entitlement process.
Disadvantages/Limitations:
For all databases, security solutions are not equally created.
Local unauthorized access is not protected.
User- Based Application monitoring for multitier environments is not supported.
Can't detect or identify the SUDU users
Cost:
The tool is licensed by number of modules and instances. The tool offers three modules:
Vulnerability Management
Rights Management
Activity Monitoring
The product is licensed separately for each database that needs to be protected. Each license comes with annual maintenance. Actual Pricing will be given by Trustwave based on your environments to support.
Recommendation for DbProtect: Yes
It offers a good support to all its customers. The management and reporting is done by a web based interface, scan results and reports are displayed based on roles, groups and rights such as whether the end user is an auditor or an administrator.
DbProtect has a central management console, central data warehouse and also a set of scanners distributed all over the client’s environment. The DbProtect and sensors are intentionally placed close to Databases being protected.
Related Questions
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.