Hi Roger, Yes! Guardium can be leveraged to Protect Data Exfiltration and would be more effective/comprehensive if we do the below.
Firstly, End Point Protection should be in place to NOT allow untrusted devices USB devices.
- Protect the DB credentials in a Privilege Credential (PAM) Vault with Password rotation)
- Enable Multi-factor when accessing highly sensitive DB credentials.
- Integrate Guardium with a SIEM solution like QRadar to Alert suspicious DB activity like Data Extraction, Unusual User activity with UEBA
- Automate incident response to isolate the Endpoint if it's a PC, block the IP from network. Detect and respond if USB device is installed/attached to a sensitive system.
Hope this helps with some insights.
Regards,
Rama Yenumula
------------------------------
Rama Yenumula
------------------------------
Original Message:
Sent: Mon October 02, 2023 05:21 AM
From: Roger Gong
Subject: Introduction to Protecting Cloud Databases using IBM Guardium
Can IBM Guardium protect the DB login to DB? What if someone is using strace/truss to attach to the DB login process? Just wondering how Guardium can protect the DB. When the attacker got the DB login password, can't the attacker dump the DB contents, save it to a USB device, and then take it away?
------------------------------
Roger Gong
Original Message:
Sent: Wed September 13, 2023 01:29 PM
From: Tushar Agrawal
Subject: Introduction to Protecting Cloud Databases using IBM Guardium
Introduction to Protecting Cloud Databases using IBM Guardium
Enterprises face growing security challenges as masses of data shift to the cloud. Loss of visibility and control over data in the cloud increases risk, making organizations a perfect target for threat actors.
To hear experts discuss how to get started on monitoring your cloud databases, join us for this informative webinar. During the webinar, you will:
- Understand the various methods of monitoring cloud databases with Guardium.
- Learn how to get started with cloud database monitoring with examples using:
- Guardium Universal Connector
- Guardium External S-TAP
Don't miss the opportunity to get introduced to cloud database monitoring with Guardium Data Protection.
Speakers:
Art Cantu, Kalyan Tatavarthy, Rajesh Gangavarapu
Security Customer Success Architect
Date & Time:
Friday, September 29, 2023
11:00 AM | (UTC-05:00) Central Time (US & Canada) | 1 hr.
------------------------------
Tushar Agrawal
------------------------------