{"id":8417,"date":"2019-09-30T16:27:06","date_gmt":"2019-09-30T16:27:06","guid":{"rendered":"https:\/\/www.crossjoin.pt\/?p=8417"},"modified":"2026-07-08T16:18:43","modified_gmt":"2026-07-08T16:18:43","slug":"the-database-audit-conundrum","status":"publish","type":"post","link":"https:\/\/crossjoin.com\/pt\/the-database-audit-conundrum\/","title":{"rendered":"O Dilema da Auditoria de Bases de Dados"},"content":{"rendered":"<div class=\"wp-block-image\">\n<figure class=\"alignleft\"><img decoding=\"async\" src=\"https:\/\/www.crossjoin.pt\/wp-content\/uploads\/2019\/09\/Artigo-Fernando-1024x695.jpg\" alt=\"Database Article\" class=\"wp-image-8418\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><br><\/p>\n\n\n\n<h6 class=\"wp-block-heading\"><span style=\"color: #ff0000;\"><span style=\"color: #333333;\">por<\/span> Fernando Ohana <\/span><span style=\"color: #333333;\">DBA and Database Security Architect<\/span><\/h6>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-1 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">Database solutions have become ubiquitous in today\u2019s technological world. DataBase Management Systems (DBMS)&nbsp; has evolved greatly since the 80\u2019s making it easier to install and deploy database centric solutions. Now, it\u2019s fair to say that the majority of companies, regardless of its size, have some sort of Database to facilitate business.<\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-2 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">The number of database solutions not only increased in absolute numbers, but also the amount of information being stored skyrocketed. In other words, the size of databases is growing at a larger pace than ever, as well as the variety of information therein. And, in this scenario, companies are gathering and storing highly sensitive information:<\/span><\/p>\n\n\n\n<ul class=\"wp-block-list has-white-color has-text-color has-link-color wp-elements-3\">\n<li><span style=\"font-weight: 400; color: #000000;\">Inside information: companies are depending upon technology to improve its business by adopting systems to increase performance and handle internal information faster;<\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400; color: #000000;\">From external parties: companies are now using information to have closer relations with clients, partners and suppliers. Therefore, a number of critical and external information is stored.<\/span><\/li>\n<\/ul>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-4 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">As a famous Uncle Ben once said: \u201cWith great power comes great responsibility\u201d. Collecting, storing and processing sensitive and confidential information has become a major challenge in a highly connected world. Securing these data from threats is a highly demanding task, especially when these threats might come in all shapes and forms: Terrorism; Vandalism; Theft; Hackitivism\u2026<\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-5 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">With a growing amount of sensitive and confidential information, spanning from personal data to financial data, company daily memos to sensitive trade secrets &#8211; protecting these assets has become paramount. It is imperative to understand how each and every business object translates to database objects. Keeping track of sensitive and confidential information within the database is crucial to the development of secure solutions. This means that one has to know their data design in order to guarantee its protection &#8211; know your business.<\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-6 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">Recognizing the need for a stronger approach in security, a number of laws have been passed to ensure companies would do their due diligence to safeguard these data. Not only that, certain industries also require high-level security to manipulate critical information.&nbsp;<\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-7 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">The most famous security requirements come from the following:<\/span><\/p>\n\n\n\n<ul class=\"wp-block-list has-white-color has-text-color has-link-color wp-elements-8\">\n<li><span style=\"color: #000000;\"><b>SOX &#8211; Sarbanes-Oxley Act <\/b><span style=\"font-weight: 400;\">&#8211; compliance is mandatory to each and every company listed in the United States NY Stock Exchange. Its goal is to safeguard companies\u2019 financial information to prevent tampering and manipulation;<\/span><\/span><\/li>\n\n\n\n<li><span style=\"color: #000000;\"><b>GDPR &#8211; General Data Protection Rule<\/b><span style=\"font-weight: 400;\"> &#8211; Is the recent law passed within the EU to ensure that personal data goes through a process that mitigates or minimizes the risk exposure;<\/span><\/span><\/li>\n\n\n\n<li><span style=\"color: #000000;\"><b>PCI DSS &#8211; Payment Card Industry Data Security Standard<\/b><span style=\"font-weight: 400;\"> &#8211; is not a law per se, but is demanded by the Payment Card industry for each and every company to manipulate credit card data.<\/span><\/span><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading has-white-color has-text-color has-link-color wp-elements-9\"><b style=\"color: #000000; font-size: 25px;\">God-like Creatures &#8211; DBA controls Database Management Systems<\/b><\/h3>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-10 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">In response to these laws and standards, one of the most difficult tasks is to secure and protect Database from internal access, usually regarded as safe. The Database Administrator (DBA) is responsible for maintaining databases and its\u2019 servers, for that they require high privileges and direct access to these servers. Ultimately they are supposed to be the most privileged users in these \u201crealms\u201d, controlling every major aspect of database systems\u2019 behavior.&nbsp;<\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-11 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">DBA is a role that requires a lot of trust and confidence in the professional\u2019s technical skills, as well as their character and ethics. Companies, however, should not operate solely on the basis of trust. They have to implement ways to mitigate these risks and put some control over the activities a DBA executes.<\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-12 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">There are, basically, two ways to tackle this issue:<\/span><\/p>\n\n\n\n<ul class=\"wp-block-list has-white-color has-text-color has-link-color wp-elements-13\">\n<li>\n<ul class=\"wp-block-list\">\n<li><span style=\"font-weight: 400; color: #000000;\">Use DBMS\u2019 native auditing;<\/span><\/li>\n\n\n\n<li><span style=\"color: #000000;\">Use 3rd-party tools.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading has-white-color has-text-color has-link-color wp-elements-14\"><b style=\"color: #000000; font-size: 25px;\">DBMS Native Auditing<\/b><\/h3>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-15 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">As implied, this auditing functionality comes embedded with the DBMS and can be activated\/deactivated from within the database server\/instance. Furthermore, it is usually easier to implement and operate.<br><\/span><br><b style=\"color: #000000; font-size: 18px;\">3 Elephants in a China Store<\/b><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-16 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">Looking at a practical standpoint, the use of native auditing poses three major problems:<\/span><\/p>\n\n\n\n<ol class=\"wp-block-list has-white-color has-text-color has-link-color wp-elements-17\">\n<li><span style=\"color: #000000;\"><b>High impact on performance<\/b><span style=\"font-weight: 400;\">: estimates suggest that turning auditing might cause up to 20% degradation;<\/span><\/span><\/li>\n\n\n\n<li><span style=\"color: #000000;\"><b>Lack of Control of Auditing activities:<\/b><span style=\"font-weight: 400;\"> auditing administration still resides within the database realm, where DBAs have full control and can manipulate and tamper with the generated audit data;<\/span><\/span><\/li>\n\n\n\n<li><span style=\"color: #000000;\"><b>Integrating Different Data:<\/b><span style=\"font-weight: 400;\"> Audit Data is generated in proprietary format, thus centralizing and consolidating data from different technologies might be cumbersome.<\/span><\/span><\/li>\n<\/ol>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-18 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\"><br>In short, the use of native auditing technology can be seen as a sort of inexpensive solution, since it does not require additional licensing. However, the hidden costs can be quite daunting, especially when they come as a surprise.<\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-19 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">To put it simply, going with native auditing \u201ccosts\u201d up to 20% of server performance, plus the amount of time needed to parse, consolidate and report upon all audit data gathered. Moreover, the \u201ccherry on top\u201d is the fact that DBAs, one of the main subjects of database auditing, can turn it on\/off at their discretion.<\/span><\/p>\n\n\n\n<h3 class=\"wp-block-heading has-white-color has-text-color has-link-color wp-elements-20\"><span style=\"color: #000000; font-size: 25px;\"><b>3rd-Party Tools<\/b><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"color: #000000;\">Referred to as Database Firewalls or Database Activity Monitoring, these tools are vendor neutral and work well with all the major brands of commercial database engines. Understanding these solutions\u2019 architecture it is easy to see how each of the previous 3 \u201celephants\u201d can be tackled:<\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-21 wp-block-paragraph\"><b style=\"color: #000000; font-size: 18px;\">To each its own<br><\/b><span style=\"color: #000000;\">These solutions are usually implemented as Appliances. This means that most of the auditing capabilities are executed outside the Database Server, thus preserving the server\u2019s processing time to do what it\u2019s supposed to.<\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-22 wp-block-paragraph\"><strong><span style=\"color: #000000;\">Appliance-based solutions limit the performance degradation to around 5%<\/span><span style=\"color: #000000;\">.<\/span><\/strong><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-23 wp-block-paragraph\"><span style=\"color: #000000; font-size: 18px;\"><b>Hands off my process<br><\/b><\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-24 wp-block-paragraph\"><span style=\"color: #000000;\">Best practices\u2019 in implementing Database Security state one should not audit him\/herself. Therefore, DBAs should have no control whatsoever over the auditing processes.<\/span> <strong style=\"font-size: 16px;\"><span style=\"color: #000000;\">The use of external tools allow Security and Audit personnel to ensure that data has not been manipulated or tampered with.<\/span><\/strong><b><br><\/b><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-25 wp-block-paragraph\"><span style=\"color: #000000; font-size: 18px;\"><b>Eureka Moment<\/b><\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-26 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">These solutions that are vendor neutral will work with the major commercial database engines. Centralizing audited data in the same repository allows the generation of integrated and consolidated reports, providing a full view of audit trails for the database entire environment.<\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-27 wp-block-paragraph\"><span style=\"color: #000000;\"><span style=\"font-weight: 400;\">The ability to report and gather information from consolidated data allows for better tracking of DBA\u2019s, and other privileged users, activities. Furthermore, <strong>with the <\/strong><\/span><strong>ability to generate alerts and full reporting capabilities make identifying deviations a bit simpler.<\/strong><\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-28 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">Also, it is worth mentioning that in a world of developing Security Environment, the adoption of the same tool for all the different brands of Database Software makes it easier to integrate with SIEMs and other Log Management solutions for broad spectrum analysis, correlating internal database events with external events elsewhere identifying overall trends and\/or problems.<\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-29 wp-block-paragraph\"><b style=\"color: #000000; font-size: 18px;\">Cutting to the chase<\/b><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-30 wp-block-paragraph\"><span style=\"color: #000000;\"><span style=\"font-weight: 400;\">When all is said and done, the design of security solutions might come in all shapes and forms. It can be cutting edge, expensive technology, but it can also be homegrown based on open-source technology. The architecture should be based on the security requirements, to implement the most adequate and efficient solution possible. Nevertheless, what matters is the possibility of answering <\/span><b>Who<\/b><span style=\"font-weight: 400;\"> did <\/span><b>What<\/b><span style=\"font-weight: 400;\">, <\/span><b>Where<\/b><span style=\"font-weight: 400;\">, <\/span><b>When<\/b><span style=\"font-weight: 400;\"> e <\/span><b>How<\/b><span style=\"font-weight: 400;\">?<\/span><\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-31 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">When designing the solution, one should consider, at least, a few variables:<\/span><\/p>\n\n\n\n<ul class=\"wp-block-list has-white-color has-text-color has-link-color wp-elements-32\">\n<li>\n<ul class=\"wp-block-list\">\n<li><span style=\"color: #000000;\"><b>Cost<\/b><span style=\"font-weight: 400;\"> &#8211; the existing budget is one of the most important constraints;<\/span><\/span><\/li>\n\n\n\n<li><span style=\"color: #000000;\"><b>Level of details<\/b><span style=\"font-weight: 400;\"> &#8211; how much information should be collected?;<\/span><\/span><\/li>\n\n\n\n<li><span style=\"color: #000000;\"><b>Duration<\/b><span style=\"font-weight: 400;\"> &#8211; for how long should audit trails be kept?<\/span><\/span><\/li>\n\n\n\n<li><span style=\"color: #000000;\"><b>Reasons to implement <\/b><span style=\"font-weight: 400;\">&#8211; why design and implement security? Is it mandatory due to legal obligation? Is it optional, as following standards and best practices?<\/span><\/span><\/li>\n\n\n\n<li><span style=\"color: #000000;\"><b>Existing threats <\/b><span style=\"font-weight: 400;\">&#8211; what is the environment landscape? Is it a target for any reason? Do you process or store sensitive information? Remember: \u201cIt is not paranoia if you are really being chased!\u201d;<\/span><\/span><\/li>\n\n\n\n<li><span style=\"color: #000000;\"><b>Exposures &#8211; <span style=\"font-weight: 400;\">what kind of network connectivity exists? Are systems connected directly to the internet?<\/span><\/b><\/span><\/li>\n\n\n\n<li><span style=\"color: #000000;\"><span style=\"color: #000000;\"><b>Impact on business<span style=\"font-weight: 400;\"> &#8211; security and auditing measures creates sensible overhead to day-to-day activities, therefore it should be considered what is the \u201creasonable\u201d degradation ratio resulting from these activities.<\/span><\/b><\/span><\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-33 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">Looking at all these perspectives, when developing a solution for Database Security it is paramount to determine some of these answers before-hand. Security Solutions can pose quite a massive overhead if not set correctly, therefore understanding the needs and requirements is crucial to reduce possible problems.<\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-34 wp-block-paragraph\"><b style=\"color: #000000; font-size: 18px;\">Performance is key<\/b><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-35 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">Out of all the existing variables, one that is critical do Database Solutions is Performance. Databases are expected to respond accurately and in a timely manner, so any unnecessary processing can be quite burdensome.&nbsp;<\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-36 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">There are a few best-practices that can be followed to reduce the amount of overhead:<\/span><\/p>\n\n\n\n<ul class=\"wp-block-list has-white-color has-text-color has-link-color wp-elements-37\">\n<li><span style=\"font-weight: 400; color: #000000;\">Limit the amount of information monitored and audited to what is actually required;<\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400; color: #000000;\">Maintain information so long as required to avoid hoarding of unnecessary data;<\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400; color: #000000;\">Keep processing off of Database Servers:<\/span>\n<ul class=\"wp-block-list\">\n<li><span style=\"font-weight: 400; color: #000000;\">Use external monitoring tools, if possible;<\/span><\/li>\n\n\n\n<li><span style=\"font-weight: 400; color: #000000;\">Use of native auditing tools, if required, DO NOT process data locally in the database server itself.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-38 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">These are three rules that should be used as guidelines in the architecture and design phase. However, good judgement and understanding of the requirements is a must.<\/span><\/p>\n\n\n\n<p class=\"has-white-color has-text-color has-link-color wp-elements-39 wp-block-paragraph\"><span style=\"font-weight: 400; color: #000000;\">Keep it Safe and Fast.<\/span><\/p>","protected":false},"excerpt":{"rendered":"<p>by Fernando Ohana DBA and Database Security Architect Database solutions have become ubiquitous in today\u2019s technological world. DataBase Management Systems (DBMS)&nbsp; has evolved greatly since the<span class=\"excerpt-hellip\"> [\u2026]<\/span><\/p>\n","protected":false},"author":2,"featured_media":8418,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"rs_blank_template":"","rs_page_bg_color":"","slide_template_v7":"","footnotes":""},"categories":[74,53],"tags":[76,77,58,78],"class_list":["post-8417","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles","category-crossjoin","tag-5g","tag-6g","tag-crossjoin","tag-iot"],"acf":[],"_links":{"self":[{"href":"https:\/\/crossjoin.com\/pt\/wp-json\/wp\/v2\/posts\/8417","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/crossjoin.com\/pt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crossjoin.com\/pt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crossjoin.com\/pt\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/crossjoin.com\/pt\/wp-json\/wp\/v2\/comments?post=8417"}],"version-history":[{"count":2,"href":"https:\/\/crossjoin.com\/pt\/wp-json\/wp\/v2\/posts\/8417\/revisions"}],"predecessor-version":[{"id":27541,"href":"https:\/\/crossjoin.com\/pt\/wp-json\/wp\/v2\/posts\/8417\/revisions\/27541"}],"wp:attachment":[{"href":"https:\/\/crossjoin.com\/pt\/wp-json\/wp\/v2\/media?parent=8417"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crossjoin.com\/pt\/wp-json\/wp\/v2\/categories?post=8417"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crossjoin.com\/pt\/wp-json\/wp\/v2\/tags?post=8417"}],"curies":[{"name":"bom jogo","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}