 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sister CISA CISSP &#187; SAP</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/cisa-cissp/tag/sap/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/cisa-cissp</link>
	<description></description>
	<lastBuildDate>Tue, 19 Oct 2010 17:25:29 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>How to Audit Databases:  Part I</title>
		<link>http://itknowledgeexchange.techtarget.com/cisa-cissp/how-to-audit-databases-part-i/</link>
		<comments>http://itknowledgeexchange.techtarget.com/cisa-cissp/how-to-audit-databases-part-i/#comments</comments>
		<pubDate>Thu, 21 Aug 2008 15:48:36 +0000</pubDate>
		<dc:creator>Arian Eigen Heald</dc:creator>
				<category><![CDATA[Admins and Auditors]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Database security]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[IT audit]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[SAP]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SOX]]></category>
		<category><![CDATA[SQL Server]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/cisa-cissp/how-to-audit-databases-part-i/</guid>
		<description><![CDATA[Databases are enormous, powerful repositories of data. They can hold payroll, HR personnel data (think social security numbers) stock prices, Accounts Receivable, Client Relationship Management, and customer information. Banks can&#8217;t live without them. Most medium and many small sized businesses use them, too. They are the motherlode of the organization and the last line of [...]]]></description>
				<content:encoded><![CDATA[<p>Databases are enormous, powerful repositories of data.  They can hold payroll, HR personnel data (think social security numbers) stock prices, Accounts Receivable, Client Relationship Management, and customer information.  Banks can&#8217;t live without them. Most medium and many small sized businesses use them, too.</p>
<p>They are the motherlode of the organization and the last line of defense in a hack.  It&#8217;s critical that DBAs have the tools at their disposal to monitor and provide reporting. If your database isn&#8217;t secure, the hacker won&#8217;t care how well indexed it is.</p>
<p>And there are a lot of ways in.  If I have administrative access to the server, I can copy all the database </em>files,<em> take them away and reload them on my own database server.  If I have unencrypted backups of those files, I can do the same thing.</em></p>
<p>So the first step in auditing the database is to examine the server the database is running on. This gets confusing to non-DBAs and auditors because many of the terms used inside the database are similiar to server terms.  It&#8217;s important to keep them separate, and to make sure that access to the database files <em>on the server</em> is monitored. Server administrators do not need to have access to those files, but they may have to, in order to manage/backup the server. So, set up logging.<br />
Make sure everyone who has a need to access that server administratively has a unique ID. Remove access to root(*NIX) or Administrator (Windows). They can have administrative rights, just make sure you can identify them by ID and IP connection.</p>
<p>Finally, what about the backup tapes?  If they are not encrypted, you can join the &#8220;breach list&#8221; of companies that have lost their data when tapes were misplaced, stolen, or &#8220;disappeared.&#8221;</p>
<p><strong>NEXT:  Inside the Database &#8220;Server&#8221;</strong></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/cisa-cissp/how-to-audit-databases-part-i/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I Can Make Your Database Lie to You</title>
		<link>http://itknowledgeexchange.techtarget.com/cisa-cissp/i-can-make-your-database-lie-to-you/</link>
		<comments>http://itknowledgeexchange.techtarget.com/cisa-cissp/i-can-make-your-database-lie-to-you/#comments</comments>
		<pubDate>Tue, 19 Aug 2008 13:20:10 +0000</pubDate>
		<dc:creator>Arian Eigen Heald</dc:creator>
				<category><![CDATA[Admins and Auditors]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Database security]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[IT audit]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[SAP]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SOX]]></category>
		<category><![CDATA[SQL Server]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/cisa-cissp/i-can-make-your-database-lie-to-you/</guid>
		<description><![CDATA[So many financial auditors, CEOs, CFOs and others rely on electronic data to understand the complexities of General Ledger, Accounts Payable, etc. In this era of SAP, ADP, electronic time clocks, etc., the one common denominator is the database underlying each application. Applications aren&#8217;t something you just run on one PC anymore (I know I&#8217;m [...]]]></description>
				<content:encoded><![CDATA[<p>So many financial auditors, CEOs, CFOs and others rely on electronic data to understand the complexities of General Ledger, Accounts Payable, etc.  In this era of SAP, ADP, electronic time clocks, etc., the one common denominator is the <em>database underlying each application</em>.</p>
<p>Applications aren&#8217;t something you just run on one PC anymore (I know I&#8217;m preaching to the choir, here). Financial applications, especially, are all networked, and the storage is usually a relational database like Oracle, MS SQL, Sybase, DB2 or MySQL.  Relational databases are wonderful for business because you can correlate so many different facts.</p>
<p>So why are they so scary to me?  Because they are rarely audited. </p>
<p>I need a network ID to log in, so the database is safe, right?  No.</p>
<p>The application has security controls, so my database is safe, right?  No.</p>
<p>DBAs (Database Administrators) know exactly what I am talking about here. All those items are just the outer edge of security.  If I have a network jack and a database ID and password, I can bypass those controls easily.</p>
<p>Some applications have a database ID and no password, or an easy-to-guess password. And very frequently, that ID has access to everything, including reads, writes and deletes.</p>
<p>If I have that ID and a network jack, I can log into your database using ODBC, Microsoft&#8217;s Open DataBase Connection client software that is installed by default on Windows operating systems. I can use Excel, Access, or other database software to pull all your data out.</p>
<p>Or <em>change</em> your data.</p>
<p>And P.S., connecting with ODBC uses clear text usernames and passwords, which is how I once captured a DBA&#8217;s ID and password with a sniffer.</p>
<p>Fortunately for all of us, there are usually other financial controls that can capture errors or changes in the database. Usually.</p>
<p><strong>NEXT:  How to Audit Databases</strong></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/cisa-cissp/i-can-make-your-database-lie-to-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
