This article presents an IT auditor's view of DB2 database risks, controls and security. We see this area as especially important due to the increasing attacks on IBM DB2 and other commercial databases that have resulted in the disclosure of confidential data.
This article presents an IT auditor's view of DB2 database risks, controls and security. We see this area as especially important due to the increasing attacks on IBM DB2 and other commercial databases that have resulted in the disclosure of confidential data.
An understanding of risks and controls is the first step in any IT audit. Controls are reviewed for proper design and then tested for effectiveness. This approach is fundamental to IT auditing and a prerequisite to effective security.
In this article, we want to highlight the correlation of the most critical DB2 risks and controls gleaned from different sources of database security best practices. As discussed below, there is some consensus on database security and the underlying risks and controls that are essential to database auditing.
An article in the IBM Technical Library titled '12 DB2 Security Best Practices' provides valuable guidance on DB2 risks and controls. Another source of
information in this area is an excellent white paper titled 'Top Ten Database
Security Threats' published by the well-respected industry vendor Imperva. These documents can be very useful to IT auditors as well as database administrators in understanding the risks in their DB2 environments.




