Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

Objective: Explore automated tool that aids in database security auditing. State

ID: 3822504 • Letter: O

Question

Objective: Explore automated tool that aids in database security auditing.
Statement: Us the materials covered in chapter 9 (Security Auditing) and the Interent to find one automated tool that aides in database security auditing. Write an essay comprises summary of your finding including but not limited to the tool:
-name
-Discerption Advantages and disadvantages
-Cost
-Your recommendation about this tool this including a justification statement for using it or not
-(It is NOT recommended to install the tool).

Explanation / Answer

Name of Tool: DbProtect

This tool is a database security auditing software which helps with the activity monitoring in the databases, vulnerability assessments and prevents data breaches. It can lock block and terminate functions immediately as quick as malicious activity is detected.

DbProtect scans through all the vulnerabilities found in the databases, configuration errors or installation and access issues.

Advantages:

Support for all major database platforms.

Automated Scans for large environment

Database vulnerability remediation scripts are available.

Reporting feature for the tool will give a pictorial/graphical representation of vulnerabilities, threats and compliance across the database environment.

Reports can be schedule and emailed automatically as required by the appropriate personnel.

Identifies the privileged users and saves time by automating the entitlement process.

Disadvantages/Limitations:

For all databases, security solutions are not equally created.

Local unauthorized access is not protected.

User- Based Application monitoring for multitier environments is not supported.

Can't detect or identify the SUDU users

Cost:

The tool is licensed by number of modules and instances. The tool offers three modules:

Vulnerability Management

Rights Management

Activity Monitoring

The product is licensed separately for each database that needs to be protected. Each license comes with annual maintenance. Actual Pricing will be given by Trustwave based on your environments to support.

Recommendation for DbProtect: Yes

It offers a good support to all its customers. The management and reporting is done by a web based interface, scan results and reports are displayed based on roles, groups and rights such as whether the end user is an auditor or an administrator.

DbProtect has a central management console, central data warehouse and also a set of scanners distributed all over the client’s environment. The DbProtect and sensors are intentionally placed close to Databases being protected.