About
Subscribe

ISS enters database security market

Johannesburg, 04 Jan 1999

Internet Security Systems (ISS), the provider of adaptive network security solutions, has announced the worldwide availability of Database Scanner 1.0, a solution for proactively securing information assets stored in database management systems (DBMS) such as Microsoft SQL Server and Sybase Adaptive Server.

The addition of Database Scanner to ISS`s SAFEsuite family of vulnerability and intrusion detection products enables customers to automate the security assessment of database servers - a new area of security risks that make up a critical part of overall enterprise security management.

Database Scanner is the result of ISS`s October acquisition of DbSecure`s technology.

"As the amount of critical networked information residing in databases continues to grow, these enterprise data repositories have rapidly become another key area of risk that needs to be closely managed," says Dov Herdan, MD of local distributor SMC Electronic Commerce (SMCec).

Database Scanner`s flexible architecture enables customers to set and enforce specific database security policies to control appropriate database activity. Users can also create policies specific to different database servers in a networked environment. Once the security policy has been established, Database Scanner performs a thorough audit, resulting in a baseline from which to measure and control security risks and facilitate continuous security improvement.

Database Scanner scans databases across a network to detect a wide range of database-specific security vulnerabilities, assessing all security risks associated with the authentication, authorisation and system integrity settings.

Key areas of Database Scanner vulnerability detection include:

  • Year 2000 compliance: Analyses database environments and reports Year 2000 compliance conflicts in data and procedures.

  • Passwords, logins and users: Performs automated password strength analysis, tracking of past users who still have login capabilities (stale logins) and checks the integrity of user names.

  • Configuration: Verifies whether or not potentially damaging functions are allowed and advises whether or not configuration options should be changed, such as replication, mail, direct updates, login auditing, existence of startup stored procedures, alerts and scheduled tasks, Web tasks, trace flags and different network protocols.

  • Tracks installation: Footprints positioning of hot fixes and service packs and informs customers of patches that still need to be installed.

  • Permission control: Determines who has access to stored procedures and alerts when there is a possible threat of database users gaining unauthorised permission on Windows NT files and resources. It also checks for the existence of Trojan horses.

Corrective actions

Once a database security audit is complete, Database Scanner provides expert analysis of the security profile with a series of meaningful graphical reports. Database Scanner also provides corrective actions for eliminating security risks.

  • SMCec is a company in the JSE-listed EC-Hold group.

Share

Editorial contacts

Frank Heydenrych
Frank Heydenrych Consultants
(011) 452 8148
frank@fhc.co.za