No current events.

Tweets

Employees Ignore #SocialMedia Policies, Play “FarmVille” on Company Time [STUDY]: http://bit.ly/cjpWxR
RSA: Banking trojan uses #social network as command and control server http://bit.ly/9xujDi #security
http://bit.ly/cVl1mr Hospital: files with personal, medical data on 800,000 gone ->#HIPAA violation
RT @SantaRosaHealth: CMS Lightens Meaningful-Use Requirements for #EHRs http://bit.ly/bLmYtR #ARRA #HITECH
Fla stolen laptops: Its nice the know the #CCTV worked really well to watch thieves steal laptops for over 9 hours! http://bit.ly/d04PFk
Database Security Assessment

Problem

Most security efforts are focused ont he application, the operating system or the network. The database is always the last to be secured yet it holds all the key information. Data confidentiality, integrity and availability is important and required a specialist in database security to truly understand the rrisks associated with a data breach.

Solution

Our Databse Security service offers a documented, comprehensive and in-depth analysis of the current security posture of existing relational databases. We perform manual and atsumated testing of database security on the database implemenation, the application accessing the database and the network architecture.  The security assessment delivers a comprehensive and in-depth analysis of the current security controls of the database. We provide technical recommendations that can be addressed byt the administrators and provides strategic solutions that can be addressed by Security Managers, Auditors, Compliance Officers and senior management.  Key steps in a Databse assessment include:

shield1 Create an inventory of all database systems and use classifications
shield1 Classify data risk, monitoring capabilities and risk rating on data access
shield1 Review roles and access restrictions
shield1 Review authorizations for users, permission levels, and user management processes
shield1 Review application access, authentication, application audit and control 
shield1 Audit activity, change control processes. log review

shield1 Review network controls and detection systems 
shield1 Review reporting capabilities