Tuesday, October 5, 2010

2010 Oracle Database surveys – widespread weakness in database security and control

Two new surveys were published recently on data security and database growth. These are 2010 surveys sponsored by Oracle Corporation, conducted by Unisphere Research and published by the Independent Oracle Users Group (IOUG) – see links below.

The surveys found that there is widespread weakness and vulnerability in commercial databases. In spite of government and industry regulations around the world, there is a continuing problem of weak database security and control.

The surveys found that a majority of companies are expecting a data security incident or attack in the next 12 months. Only 30% of companies are encrypting personally identifiable information – the most sensitive data. An even smaller number of companies have controls to prevent privileged users from accessing sensitive data. Companies do not appear to have a good handle on database security.

There is much work to be done. Our opinion at Continental Audit is that this is an urgent issue. A company’s data is its ‘crown jewels.’ It should be protected accordingly.

The surveys can be found at the following URLs:
http://www.ioug.org/tabid/90/Default.aspx
http://www.oracle.com/newsletters/information-indepth/security/oct-10/iougsurvey.html?msgid=3-2401132434

No comments:

Post a Comment