Hi Francis:
I suggest you have your data security and IAM SME's review the IBM provided scripts to determine what permissions are granted. Many of ours were not comfortable executing the scripts or they did not work as part of a repeatable process, so it took us some trial and error with each db platform team to work out the permissions. We found that, typically, the minimum access is read.
We then went through all of the applicable procedures to obtain approval to deploy generic accounts. Their only function is to run the scans. We use a different account where we can to reduce the risk, but not to make it overly complex and their password is changed after every use.
We then had them provisioned to every existing database and included in the gold standard for new ones going forward. This was easier for some platforms that others, but likely depends on your companies DBA capabilities and Identity and Access Management (IAM) program.
Part of obtaining this approval included oversight, so we set up a Guardium alert that triggers if any of those accounts are used from a Client IP (source) other than the Guardium unit that we use to execute the scanning. This, of course, only works if you are also monitoring those databases.
Another tip, you may want to consider consulting with your DBA's to understand if there are schema's that are used only for the system tables. These typically do not contain user data and can be excluded from your policy rules. Guardium comes with a set of groups that you can consider as a starting point, navigate to 'Group Builder' and search for "
Excluded Classification".
I hope that some of this information helps.
Thanks!------------------------------
Wendy Zemba
------------------------------