IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Classifying a table with multiple classification

    Posted Mon May 29, 2023 02:29 PM

    We just got IBM Guradium at our enterprise and me and my colleagues are still learning about it, one of the requirements we got was to classifying a table in the DB with more than one classification. For example a table can have a column where it contains sensitive data like (credit card info) and one where it contains the (name), how can we secure the access on the first column ? the other has to be secured of course but not as highly secured like the (credit card info). is it related to groups or a policy might solve this ? I would appreciate the help if you can.

    Thank you



    ------------------------------
    Sami Ali
    ------------------------------


  • 2.  RE: Classifying a table with multiple classification

    Posted Wed May 31, 2023 03:30 AM

    Could you elaborate what would you like to achieve when you use a "secure the access" phrase? Blocking?

    You can include many classification rules in the classification process.



    ------------------------------
    Zbigniew (Zibi) Szmigiero
    IBM
    Międzyrzecz
    ------------------------------



  • 3.  RE: Classifying a table with multiple classification

    Posted Wed May 31, 2023 08:26 AM

    Maybe i didn't explian it properly, what i mean is can a specific column in a table be classified only and not the whole table ? 



    ------------------------------
    Sami Ali
    ------------------------------



  • 4.  RE: Classifying a table with multiple classification

    Posted Thu June 01, 2023 05:06 AM

    Sami,
    G classification engine provides you a two methods of classification:
    - based on metadata: table, column name (not really valuable in most cases, because of false negatives)
    - base on content
    The second approach always provide you information about the table and column name where the specific data type has been identified.



    ------------------------------
    Zbigniew (Zibi) Szmigiero
    IBM
    Międzyrzecz
    ------------------------------



  • 5.  RE: Classifying a table with multiple classification

    Posted Wed May 31, 2023 09:15 AM

    Sami,
    It really depends on what you want to do with it.  
    At the column level, you can report on it, mask it.
    At the object level, it becomes easier to decide if you wan to act on it, block, real-time alert from Guardium database activity monitoring, create a ticket for investigation.
    So classification helps to make Guardium monitoring more meaningful by monitoring the relevant objects/data. 
    So it really comes down to what the action will be if someone selects, changes, or deletes the relevant data.



    ------------------------------
    Jennifer Dodson
    ------------------------------



  • 6.  RE: Classifying a table with multiple classification

    Posted Thu June 01, 2023 09:10 AM

    Sami,

    The classification portion of Guardium will include the table and column.

    When you say "secure" access, then you are getting down to the policy level.  Guardium does allow object and field and object/field groups you can define. I have a test case myself where one column is highly sensitive and can be in many tables across the enterprise. So I created an object/field based Guardium rule. 

    So at the policy level, you can use groups of fields to secure the access.  There are some restrictions by database platform. But typically if you can use Data Classification, then that platform can likely perform the appropriate action in the policy.

    Jennifer



    ------------------------------
    Jennifer Dodson
    Security Technical Professional
    Global Sales, Financial Services
    1 469 502 8850 Mobile
    jennifer.dodson@ibm.com

    IBM
    ------------------------------



  • 7.  RE: Classifying a table with multiple classification

    Posted Fri June 02, 2023 03:15 AM
    Edited by Sami Ali Fri June 02, 2023 03:16 AM

    Many thanks Zibi and Jennifer, we'll try by getting down to poilcy level after we create an object/field rule. As for the metadata approach indeed we got some false negatives so we are not focusing on it for now. Really appreciate the help



    ------------------------------
    Sami Ali
    ------------------------------