« Countering the Threat of Information Security Fatigue | Main | Better Authentication Needed to Counter Man-in-the-Middle Attacks »

Database Security - Patching is not enough

Next Tuesday, 16th January 2007, Oracle will issue 52 critical patches. It’s clearly a great leap forward for database vulnerability management. But it also illustrates the size of our security exposure at the application level. Any company that relies on database security measures to safeguard critical business processes or sensitive personal data should be very afraid. The security threat landscape is now focused on espionage and data theft. Efficient patching will not be sufficient. We need a step change in the application of good security practices throughout the system development cycle. And we need to take steps to secure our intrinsically insecure legacy systems. Organizations should not simply wait for the next set of fixes to known vulnerabilities. They should identify their critical applications, assess the security risks associated with them and immediately apply additional security measures to prevent external and internal attempts to exploit potential weaknesses. There is plenty of affordable security technology on the market to help with this. So there's no longer any technical excuse for not keeping your critical and sensitive data under control.

Bookmark and Share


TrackBack

TrackBack URL for this entry:
http://www.computerweekly.com/cgi-bin/mt/mt-tb.cgi/1717

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on January 12, 2007 8:39 PM.

The previous post in this blog was Countering the Threat of Information Security Fatigue.

The next post in this blog is Better Authentication Needed to Counter Man-in-the-Middle Attacks.

Many more can be found on the main index page or by looking through the archives.