As a former developer, new IT security products show me that I was wrong. It is possible to store all DB activities for security and compliance reasons. What I considered impossible is being sold nowadays and has been running in production at financial institutions for 15 years.
“All database activities are stored with a granularity of five minutes,” claims the founder of a company I work with. He is talking about Core Audit from the company Blue Core Research. After familiarising myself with the product and asking many technical questions, I have to say that the claim is true. I analyzed the implementation details and found that all the difficult aspects regarding performance loss and storage space consumption have been cleverly solved.
This is a relief for data protection officers, CISOs, CTOs and database administrators. When the logging of accesses to personal or financial data is configured selectively, some tables, accounts and programs may still not be captured. They will then not be included in the reports for auditors either. Furthermore, you do not know how internal employees or external attackers will deliberately copy our data, so not all possibilities can be covered by the log.
License costs, performance loss or storage space consumption are no longer reasons to log too little.
With this security log, you can prove when a data leak occurred and from where, how many rows were affected and which SQL statements were executed. You can also answer questions from external auditors regarding IT security incidents and continuously check whether the database connections and activities comply with our security policies.
What have you recently learned in IT security that showed you that you had been wrong for years?
The image shows the detection of a data leak using Core Audit from the company Blue Core Research
