IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Datasource Definition - User Permission

    Posted 05/18/20 04:39 AM
    Hi,

    Im new to this group and trying to figure out more about datasource definitions, especially to be used on discovering sensitive data and classification.
    Is there a documentation or in your experience, what is the least privilege credential we can use in the definition for doing this (discovering sensitive data and classification)? Some agencies are not allowed to use the sa or db2inst. How do I go about this? I would appreciate your feedback or assistance on this.

    Cheers...

    ------------------------------
    ------------------------------
    Francis Bebita
    ------------------------------
    ------------------------------


  • 2.  RE: Datasource Definition - User Permission

    Posted 05/18/20 06:33 AM

    Hi Francis,

    First welcome!

    Please review the below link:
    https://www.ibm.com/support/knowledgecenter/SSMPHH_11.1.0/com.ibm.guardium.doc/assess/va_scripts.html

    We supply scripts that assign the permissions required to execute classification.  These assign permissions that we require and have tested with.  If their is a specific permission that you are concerned about then you can open a case and make further enquries but input from development is likely to be needed.

    I hope that helps..



    ------------------------------
    MARK HARRIS
    ------------------------------



  • 3.  RE: Datasource Definition - User Permission

    Posted 05/18/20 07:56 AM
    Hi Francis:

    I suggest you have your data security and IAM SME's review the IBM provided scripts to determine what permissions are granted.   Many of ours were not comfortable executing the scripts or they did not work as part of a repeatable process, so it took us some trial and error with each db platform team to work out the permissions.  We found that, typically, the minimum access is read.

    We then went through all of the applicable procedures to obtain approval to deploy generic accounts.  Their only function is to run the scans.  We use a different account where we can to reduce the risk, but not to make it overly complex and their password is changed after every use.

    We then had them provisioned to every existing database and included in the gold standard for new ones going forward.  This was easier for some platforms that others, but likely depends on your companies DBA capabilities and Identity and Access Management (IAM) program. 

    Part of obtaining this approval included oversight, so we set up a Guardium alert that triggers if any of those accounts are used from a Client IP (source) other than the Guardium unit that we use to execute the scanning.  This, of course, only works if you are also monitoring those databases.

    Another tip, you may want to consider consulting with your DBA's to understand if there are schema's that are used only for the system tables.  These typically do not contain user data and can be excluded from your policy rules.  Guardium comes with a set of groups that you can consider as a starting point, navigate to 'Group Builder' and search for "Excluded Classification".

    I hope that some of this information helps. 

    Thanks!


    ------------------------------
    Wendy Zemba
    ------------------------------