SlideShare uma empresa Scribd logo
1 de 41
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Maintaining Regulatory Compliance and
Security in Challenging Conditions
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 2
Hello and Welcome!
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 3
Agenda
▪ The connection between security and compliance
▪ What is Personal Data?
▪ Why is personal data collected?
▪ Concerns over data privacy
▪ Protecting sensitive data in SQL Servers
▪ Database security vulnerabilities
▪ Internal and external threats
▪ Challenges posed by the COVID-19 pandemic
▪ Demonstrating regulatory compliance for SQL Servers
▪ Complications of regulatory diversity
▪ Detailed look at GDPR
▪ Internal Audits
▪ External Audits
▪ Challenges posed by the COVID-19 pandemic
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 4
Agenda Continued
▪ Dangers of lax security
▪ Dangers of noncompliance
▪ IDERA’s software solutions for SQL
Server
▪ SQL Secure
▪ SQL Compliance Manager
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Security and Compliance are Connected
Security and compliance are two complimentary components that are
required to provide and verify data privacy. We are going to look at
how these elements impact IT in general and specifically SQL Server
environments.
“
© 2020 IDERA, Inc. All rights reserved. 6
“Historically, privacy was almost implicit, because it
was hard to find and gather information. But in the
digital world, whether it's digital cameras or satellites
or just what you click on, we need to have more
explicit rules - not just for governments but for
private companies.” Bill Gates
“
© 2020 IDERA, Inc. All rights reserved. 7
“Proof is the bottom line for everyone.” Paul
Simon
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Two Sides to Protecting Personal Data
Security comprises activities that protect the privacy of personal data.
Compliance involves demonstrating that the proper security measures are being
taken to protect personal data.
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Personal Data Defined
‘Personal data’ means any information relating to an identified or identifiable
natural person (‘data subject’); an identifiable natural person is one who can
be identified, directly or indirectly, in particular by reference to an identifier
such as a name, an identification number, location data, an online identifier
or to one or more factors specific to the physical, physiological, genetic,
mental, economic, cultural or social identity of that natural person.
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 10
Examples of Personal Data
• Full name
• Home address
• Bank account or credit card number
• ID number such as Social Security or driver’s
license
• Racial or ethnic origin
• Location data
• Health or medical records
• Email address
• Political or religious beliefs
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 11
Why Personal Data is Collected
▪ Creating user profiles for
personalized marketing
▪ Verifying online financial
transactions
▪ Customizing the user experience
on websites and in applications
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 12
Concerns Regarding Data Privacy
Citizens have multiple concerns
regarding the privacy of their personal
data
• Digital surveillance by corporations or
governments
• Identity theft
• Unsolicited marketing materials
• Lack of control over use and sharing of
personal data
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 13
Why Data Privacy is Essential
▪ Digital commerce
▪ Validly collected information
misused
▪ Identity theft with long-term
repercussions to the affected
individuals
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 14
The Effects of Covid-19 on Database Security
▪ Remote work means more places
need to be secured
▪ Healthcare and medical facilities are
being targeted with ransomware
▪ When setting up remote access,
elevated privileges may have been
granted
▪ Lack of oversight for file copies
▪ General anxiety leads to a greater
probability of success with phishing
emails.
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Covid-19 Related Ransomware Incidents
▪ Netwalker
▪ Boyce Technologies and the
DoppelPaymer ransomware
group
▪ Interpol - The problem is not only
in the U.S.
▪ Evolution of ransomware to
include triggering data breaches
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Database Security Vulnerabilities
• Weak passwords
• Shared passwords
• Default system passwords and settings
• Excessive and elevated privileges
• Lack of pre-deployment security testing
• Poor data encryption
• Insecure database backups
• Unnecessary database features
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Protecting Sensitive Data
• External threats
• Direct attacks
• Malware infection
• Internal threats
• Accidental misuse of data
• Intentional data misuse
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
External Threats to Sensitive Data
• External threats
• Direct attacks using
compromised credentials and
network vulnerability
• Malware infection delivered
through phishing emails or
other methods
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Internal Threats to Sensitive Data
• Internal threats
• Accidental misuse of data
due to lack of training or
human error
• Intentional misuse using
unauthorized access or
elevated privileges
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
•Geographic location or
jurisdiction of data owners
•Type of data under
consideration
•Industry or market sector in
which the data is used
Factors Affecting Data Privacy Regulations
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Geographic Location or Jurisdiction of Data Owners
• General Data Protection Regulation - GDPR
• Brazilian General Data Protection - LGPD
• New Zealand Privacy Bill
• California Consumer Privacy Act - CCPA
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
The California Consumer Privacy Act
CCPA
The California Consumer Privacy Act gives
consumers more control over the personal
information that businesses collect about them.
• The right to know about the personal information a
business collects about them and how it is used
and shared
• The right to delete personal information collected
from them (with some exceptions)
• The right to opt-out of the sale of their personal
information
• The right to non-discrimination for exercising their
CCPA rights
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Which Businesses Does CCPA
Affect?
Businesses need to follow CCPA
guidelines if they meet one of
these criteria:
▪ Have $25 million or more in
annual revenue;
▪ Possess the personal data of
more than 50,000 consumers,
households, or devices;
▪ Earn more than half of its
annual revenue selling
consumers’ personal data.
Businesses are exempt from CCPA
regulations if they are in the
following market sectors:
▪ Health providers and insurers
already under HIPAA
guidelines;
▪ Banks and financial companies
covered by Gramm-Leach-
Bliley;
▪ Credit reporting agencies
operating under the Fair Credit
Reporting Act.
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Type of Data or Industry
• Personally Identifiable Information (PII)
• Health-related information - HIPAA
• Financial disclosure information - SOX
• Credit card payment information - PCI
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 25
The Effects of Covid-19 on Regulatory Compliance
▪ Remote work locations
▪ Local copies of sensitive data
▪ Additional security
vulnerabilities that need to be
tested
▪ New protocols put in place to
address compliance gaps
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Inside GDPR
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
GDPR Data Protection Principles
1. Lawfulness, fairness, transparency
2. Purpose limitation
3. Data minimization
4. Accuracy
5. Storage limitation
6. Integrity and confidentiality
7. Accountability
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
GDPR - When You Can Process Data
1. With unambiguous consent from the data owner
2. When entering into a contract with the data owner
3. To comply with legal obligations
4. To save someone’s life
5. To perform a task in the pubic interest
6. With a legitimate interest
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
GDPR - Checklist for U.S. Companies
• Audit your environment for EU personal data
• Inform customers why you are processing their data
• Assess and improve data processing activities
• Maintain data processing agreements with vendors
• Appoint a data protection officer if necessary
• Designate a representative in the EU
• Understand the responsibilities in the event of a data breach
• Comply with cross-border data transfer laws
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Compliance Audits
A compliance audit tests the
state of your systems against a
set of regulatory standards.
Audits can be carried out by:
• Internal teams
• External agencies
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Demonstrating Compliance
• Proof!
• Reports
• Run books
• Documentation
• Configuration settings
• Security settings
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Why Compliance is Important
• Attract business by demonstrating compliance with industry
specific regulations like PCI or SOX.
• Assure customers that their data is protected in your
company’s databases.
• Avoid financial penalties levied by regulatory agencies
• Maintain a high level of customer confidence
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Keys to Regulatory Compliance
•Understanding the specific regulations that apply to your systems
•Buy-in and full support from senior management
•Implementing risk assessment measures for internal controls
•Written procedures and policies to deal with business practices
•Extensive training for management, employees and contractors
•An oversight team to enforce, monitor, audit and respond to allegations and
misconduct
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Dangers of Lax Security
• Data breaches
• System outages
• Loss of customer trust
• Inability to comply with
privacy regulations
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
Dangers of Noncompliance
• Loss of customer trust
• Loss of business opportunities
• Financial penalties
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
IDERA Solutions for SQL Server
SQL Secure
SQL Compliance Manger
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
SQL Secure
Take full control of SQL Server permissions
• Identify existing vulnerabilities in your SQL Server, Azure, and Amazon environments.
• Harden security policies across SQL Server, Azure, and Amazon SQL databases.
• Rank security levels with the security report card.
• Analyze and report on user permissions across database objects.
• Comply with audits using customizable templates for PCI, HIPAA and more.
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
SQL Compliance Manager
Monitor, audit and alert on SQL Server user activity and data changes
• Track and manage SQL Server database compliance quickly and easily.
• Audit servers, databases, and sensitive data to see who did what. when, where, and how.
• Monitor and alert on suspicious activity to detect and track potential problems.
• Satisfy audits with configurations and reports for multiple regulatory guidelines requirements.
• Reduce impact on audited servers via a lightweight data collection mechanism.
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved.
A Powerful Combination of Software Tools for SQL Server
SQL Secure enables you
to identify where
sensitive data resides
and helps you tighten up
the security of your SQL
Servers. It provides the
functionality needed to
meet data privacy
regulations and keep
personal data safe.
SQL Compliance
Manager performs the
complimentary task of
demonstrating
compliance with the
regulatory security
standards that affect the
data in your SQL
Servers.
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 40
THANKS!
Any questions?
You can find me at:
@robert.agar@idera.com
© 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 41
There icons are editable shapes.
This means that you can:
● Resize them without losing quality.
● Change fill color and opacity.
● Change line color, width and style.
Examples:

Mais conteúdo relacionado

Mais de IDERA Software

Idera live 2021: Why Data Lakes are Critical for AI, ML, and IoT By Brian Flug
Idera live 2021:  Why Data Lakes are Critical for AI, ML, and IoT  By Brian FlugIdera live 2021:  Why Data Lakes are Critical for AI, ML, and IoT  By Brian Flug
Idera live 2021: Why Data Lakes are Critical for AI, ML, and IoT By Brian FlugIDERA Software
 
Idera live 2021: Will Data Vault add Value to Your Data Warehouse? 3 Signs th...
Idera live 2021: Will Data Vault add Value to Your Data Warehouse? 3 Signs th...Idera live 2021: Will Data Vault add Value to Your Data Warehouse? 3 Signs th...
Idera live 2021: Will Data Vault add Value to Your Data Warehouse? 3 Signs th...IDERA Software
 
Idera live 2021: Managing Digital Transformation on a Budget by Bert Scalzo
Idera live 2021:  Managing Digital Transformation on a Budget by Bert ScalzoIdera live 2021:  Managing Digital Transformation on a Budget by Bert Scalzo
Idera live 2021: Managing Digital Transformation on a Budget by Bert ScalzoIDERA Software
 
Idera live 2021: Keynote Presentation The Future of Data is The Data Cloud b...
Idera live 2021:  Keynote Presentation The Future of Data is The Data Cloud b...Idera live 2021:  Keynote Presentation The Future of Data is The Data Cloud b...
Idera live 2021: Keynote Presentation The Future of Data is The Data Cloud b...IDERA Software
 
Idera live 2021: Managing Databases in the Cloud - the First Step, a Succes...
Idera live 2021:   Managing Databases in the Cloud - the First Step, a Succes...Idera live 2021:   Managing Databases in the Cloud - the First Step, a Succes...
Idera live 2021: Managing Databases in the Cloud - the First Step, a Succes...IDERA Software
 
Idera live 2021: Database Auditing - on-Premises and in the Cloud by Craig M...
Idera live 2021:  Database Auditing - on-Premises and in the Cloud by Craig M...Idera live 2021:  Database Auditing - on-Premises and in the Cloud by Craig M...
Idera live 2021: Database Auditing - on-Premises and in the Cloud by Craig M...IDERA Software
 
Idera live 2021: Performance Tuning Azure SQL Database by Monica Rathbun
Idera live 2021:  Performance Tuning Azure SQL Database by Monica RathbunIdera live 2021:  Performance Tuning Azure SQL Database by Monica Rathbun
Idera live 2021: Performance Tuning Azure SQL Database by Monica RathbunIDERA Software
 
Geek Sync | How to Be the DBA When You Don't Have a DBA - Eric Cobb | IDERA
Geek Sync | How to Be the DBA When You Don't Have a DBA - Eric Cobb | IDERAGeek Sync | How to Be the DBA When You Don't Have a DBA - Eric Cobb | IDERA
Geek Sync | How to Be the DBA When You Don't Have a DBA - Eric Cobb | IDERAIDERA Software
 
How Users of a Performance Monitoring Tool Can Benefit from an Inventory Mana...
How Users of a Performance Monitoring Tool Can Benefit from an Inventory Mana...How Users of a Performance Monitoring Tool Can Benefit from an Inventory Mana...
How Users of a Performance Monitoring Tool Can Benefit from an Inventory Mana...IDERA Software
 
Benefits of Third Party Tools for MySQL | IDERA
Benefits of Third Party Tools for MySQL | IDERABenefits of Third Party Tools for MySQL | IDERA
Benefits of Third Party Tools for MySQL | IDERAIDERA Software
 
Achieve More with Less Resources | IDERA
Achieve More with Less Resources | IDERAAchieve More with Less Resources | IDERA
Achieve More with Less Resources | IDERAIDERA Software
 
Benefits of SQL Server 2017 and 2019 | IDERA
Benefits of SQL Server 2017 and 2019 | IDERABenefits of SQL Server 2017 and 2019 | IDERA
Benefits of SQL Server 2017 and 2019 | IDERAIDERA Software
 
Be Proactive: A Good DBA Goes Looking for Signs of Trouble | IDERA
Be Proactive: A Good DBA Goes Looking for Signs of Trouble | IDERABe Proactive: A Good DBA Goes Looking for Signs of Trouble | IDERA
Be Proactive: A Good DBA Goes Looking for Signs of Trouble | IDERAIDERA Software
 
Advanced SQL Server Performance Tuning | IDERA
Advanced SQL Server Performance Tuning | IDERAAdvanced SQL Server Performance Tuning | IDERA
Advanced SQL Server Performance Tuning | IDERAIDERA Software
 
Geek Sync | Planning a SQL Server to Azure Migration in 2021 - Brent Ozar
Geek Sync | Planning a SQL Server to Azure Migration in 2021 - Brent OzarGeek Sync | Planning a SQL Server to Azure Migration in 2021 - Brent Ozar
Geek Sync | Planning a SQL Server to Azure Migration in 2021 - Brent OzarIDERA Software
 
Geek Sync | Performance Tuning: Getting the Biggest Bang for Your Buck - Moni...
Geek Sync | Performance Tuning: Getting the Biggest Bang for Your Buck - Moni...Geek Sync | Performance Tuning: Getting the Biggest Bang for Your Buck - Moni...
Geek Sync | Performance Tuning: Getting the Biggest Bang for Your Buck - Moni...IDERA Software
 
Geek Sync | Meeting Security Benchmarks and Compliance with Microsoft SQL Ser...
Geek Sync | Meeting Security Benchmarks and Compliance with Microsoft SQL Ser...Geek Sync | Meeting Security Benchmarks and Compliance with Microsoft SQL Ser...
Geek Sync | Meeting Security Benchmarks and Compliance with Microsoft SQL Ser...IDERA Software
 
Geek Sync | How to Think Like the SQL ServerEngine - Brent Ozar
Geek Sync | How to Think Like the SQL ServerEngine - Brent OzarGeek Sync | How to Think Like the SQL ServerEngine - Brent Ozar
Geek Sync | How to Think Like the SQL ServerEngine - Brent OzarIDERA Software
 
Geek Sync | Data Integrity Demystified - Deborah Melkin | IDERA
Geek Sync | Data Integrity Demystified - Deborah Melkin | IDERAGeek Sync | Data Integrity Demystified - Deborah Melkin | IDERA
Geek Sync | Data Integrity Demystified - Deborah Melkin | IDERAIDERA Software
 
Geek Sync | Breaking Bad Habits: Solutions for Common Query Antipatterns - Je...
Geek Sync | Breaking Bad Habits: Solutions for Common Query Antipatterns - Je...Geek Sync | Breaking Bad Habits: Solutions for Common Query Antipatterns - Je...
Geek Sync | Breaking Bad Habits: Solutions for Common Query Antipatterns - Je...IDERA Software
 

Mais de IDERA Software (20)

Idera live 2021: Why Data Lakes are Critical for AI, ML, and IoT By Brian Flug
Idera live 2021:  Why Data Lakes are Critical for AI, ML, and IoT  By Brian FlugIdera live 2021:  Why Data Lakes are Critical for AI, ML, and IoT  By Brian Flug
Idera live 2021: Why Data Lakes are Critical for AI, ML, and IoT By Brian Flug
 
Idera live 2021: Will Data Vault add Value to Your Data Warehouse? 3 Signs th...
Idera live 2021: Will Data Vault add Value to Your Data Warehouse? 3 Signs th...Idera live 2021: Will Data Vault add Value to Your Data Warehouse? 3 Signs th...
Idera live 2021: Will Data Vault add Value to Your Data Warehouse? 3 Signs th...
 
Idera live 2021: Managing Digital Transformation on a Budget by Bert Scalzo
Idera live 2021:  Managing Digital Transformation on a Budget by Bert ScalzoIdera live 2021:  Managing Digital Transformation on a Budget by Bert Scalzo
Idera live 2021: Managing Digital Transformation on a Budget by Bert Scalzo
 
Idera live 2021: Keynote Presentation The Future of Data is The Data Cloud b...
Idera live 2021:  Keynote Presentation The Future of Data is The Data Cloud b...Idera live 2021:  Keynote Presentation The Future of Data is The Data Cloud b...
Idera live 2021: Keynote Presentation The Future of Data is The Data Cloud b...
 
Idera live 2021: Managing Databases in the Cloud - the First Step, a Succes...
Idera live 2021:   Managing Databases in the Cloud - the First Step, a Succes...Idera live 2021:   Managing Databases in the Cloud - the First Step, a Succes...
Idera live 2021: Managing Databases in the Cloud - the First Step, a Succes...
 
Idera live 2021: Database Auditing - on-Premises and in the Cloud by Craig M...
Idera live 2021:  Database Auditing - on-Premises and in the Cloud by Craig M...Idera live 2021:  Database Auditing - on-Premises and in the Cloud by Craig M...
Idera live 2021: Database Auditing - on-Premises and in the Cloud by Craig M...
 
Idera live 2021: Performance Tuning Azure SQL Database by Monica Rathbun
Idera live 2021:  Performance Tuning Azure SQL Database by Monica RathbunIdera live 2021:  Performance Tuning Azure SQL Database by Monica Rathbun
Idera live 2021: Performance Tuning Azure SQL Database by Monica Rathbun
 
Geek Sync | How to Be the DBA When You Don't Have a DBA - Eric Cobb | IDERA
Geek Sync | How to Be the DBA When You Don't Have a DBA - Eric Cobb | IDERAGeek Sync | How to Be the DBA When You Don't Have a DBA - Eric Cobb | IDERA
Geek Sync | How to Be the DBA When You Don't Have a DBA - Eric Cobb | IDERA
 
How Users of a Performance Monitoring Tool Can Benefit from an Inventory Mana...
How Users of a Performance Monitoring Tool Can Benefit from an Inventory Mana...How Users of a Performance Monitoring Tool Can Benefit from an Inventory Mana...
How Users of a Performance Monitoring Tool Can Benefit from an Inventory Mana...
 
Benefits of Third Party Tools for MySQL | IDERA
Benefits of Third Party Tools for MySQL | IDERABenefits of Third Party Tools for MySQL | IDERA
Benefits of Third Party Tools for MySQL | IDERA
 
Achieve More with Less Resources | IDERA
Achieve More with Less Resources | IDERAAchieve More with Less Resources | IDERA
Achieve More with Less Resources | IDERA
 
Benefits of SQL Server 2017 and 2019 | IDERA
Benefits of SQL Server 2017 and 2019 | IDERABenefits of SQL Server 2017 and 2019 | IDERA
Benefits of SQL Server 2017 and 2019 | IDERA
 
Be Proactive: A Good DBA Goes Looking for Signs of Trouble | IDERA
Be Proactive: A Good DBA Goes Looking for Signs of Trouble | IDERABe Proactive: A Good DBA Goes Looking for Signs of Trouble | IDERA
Be Proactive: A Good DBA Goes Looking for Signs of Trouble | IDERA
 
Advanced SQL Server Performance Tuning | IDERA
Advanced SQL Server Performance Tuning | IDERAAdvanced SQL Server Performance Tuning | IDERA
Advanced SQL Server Performance Tuning | IDERA
 
Geek Sync | Planning a SQL Server to Azure Migration in 2021 - Brent Ozar
Geek Sync | Planning a SQL Server to Azure Migration in 2021 - Brent OzarGeek Sync | Planning a SQL Server to Azure Migration in 2021 - Brent Ozar
Geek Sync | Planning a SQL Server to Azure Migration in 2021 - Brent Ozar
 
Geek Sync | Performance Tuning: Getting the Biggest Bang for Your Buck - Moni...
Geek Sync | Performance Tuning: Getting the Biggest Bang for Your Buck - Moni...Geek Sync | Performance Tuning: Getting the Biggest Bang for Your Buck - Moni...
Geek Sync | Performance Tuning: Getting the Biggest Bang for Your Buck - Moni...
 
Geek Sync | Meeting Security Benchmarks and Compliance with Microsoft SQL Ser...
Geek Sync | Meeting Security Benchmarks and Compliance with Microsoft SQL Ser...Geek Sync | Meeting Security Benchmarks and Compliance with Microsoft SQL Ser...
Geek Sync | Meeting Security Benchmarks and Compliance with Microsoft SQL Ser...
 
Geek Sync | How to Think Like the SQL ServerEngine - Brent Ozar
Geek Sync | How to Think Like the SQL ServerEngine - Brent OzarGeek Sync | How to Think Like the SQL ServerEngine - Brent Ozar
Geek Sync | How to Think Like the SQL ServerEngine - Brent Ozar
 
Geek Sync | Data Integrity Demystified - Deborah Melkin | IDERA
Geek Sync | Data Integrity Demystified - Deborah Melkin | IDERAGeek Sync | Data Integrity Demystified - Deborah Melkin | IDERA
Geek Sync | Data Integrity Demystified - Deborah Melkin | IDERA
 
Geek Sync | Breaking Bad Habits: Solutions for Common Query Antipatterns - Je...
Geek Sync | Breaking Bad Habits: Solutions for Common Query Antipatterns - Je...Geek Sync | Breaking Bad Habits: Solutions for Common Query Antipatterns - Je...
Geek Sync | Breaking Bad Habits: Solutions for Common Query Antipatterns - Je...
 

Último

How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilV3cube
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsRoshan Dwivedi
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...gurkirankumar98700
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 

Último (20)

How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of Brazil
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 

IDERA Live | Maintaining Regulatory Compliance and Security in Challenging Conditions

  • 1. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Maintaining Regulatory Compliance and Security in Challenging Conditions
  • 2. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 2 Hello and Welcome!
  • 3. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 3 Agenda ▪ The connection between security and compliance ▪ What is Personal Data? ▪ Why is personal data collected? ▪ Concerns over data privacy ▪ Protecting sensitive data in SQL Servers ▪ Database security vulnerabilities ▪ Internal and external threats ▪ Challenges posed by the COVID-19 pandemic ▪ Demonstrating regulatory compliance for SQL Servers ▪ Complications of regulatory diversity ▪ Detailed look at GDPR ▪ Internal Audits ▪ External Audits ▪ Challenges posed by the COVID-19 pandemic
  • 4. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 4 Agenda Continued ▪ Dangers of lax security ▪ Dangers of noncompliance ▪ IDERA’s software solutions for SQL Server ▪ SQL Secure ▪ SQL Compliance Manager
  • 5. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Security and Compliance are Connected Security and compliance are two complimentary components that are required to provide and verify data privacy. We are going to look at how these elements impact IT in general and specifically SQL Server environments.
  • 6. “ © 2020 IDERA, Inc. All rights reserved. 6 “Historically, privacy was almost implicit, because it was hard to find and gather information. But in the digital world, whether it's digital cameras or satellites or just what you click on, we need to have more explicit rules - not just for governments but for private companies.” Bill Gates
  • 7. “ © 2020 IDERA, Inc. All rights reserved. 7 “Proof is the bottom line for everyone.” Paul Simon
  • 8. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Two Sides to Protecting Personal Data Security comprises activities that protect the privacy of personal data. Compliance involves demonstrating that the proper security measures are being taken to protect personal data.
  • 9. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Personal Data Defined ‘Personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • 10. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 10 Examples of Personal Data • Full name • Home address • Bank account or credit card number • ID number such as Social Security or driver’s license • Racial or ethnic origin • Location data • Health or medical records • Email address • Political or religious beliefs
  • 11. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 11 Why Personal Data is Collected ▪ Creating user profiles for personalized marketing ▪ Verifying online financial transactions ▪ Customizing the user experience on websites and in applications
  • 12. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 12 Concerns Regarding Data Privacy Citizens have multiple concerns regarding the privacy of their personal data • Digital surveillance by corporations or governments • Identity theft • Unsolicited marketing materials • Lack of control over use and sharing of personal data
  • 13. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 13 Why Data Privacy is Essential ▪ Digital commerce ▪ Validly collected information misused ▪ Identity theft with long-term repercussions to the affected individuals
  • 14. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 14 The Effects of Covid-19 on Database Security ▪ Remote work means more places need to be secured ▪ Healthcare and medical facilities are being targeted with ransomware ▪ When setting up remote access, elevated privileges may have been granted ▪ Lack of oversight for file copies ▪ General anxiety leads to a greater probability of success with phishing emails.
  • 15. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Covid-19 Related Ransomware Incidents ▪ Netwalker ▪ Boyce Technologies and the DoppelPaymer ransomware group ▪ Interpol - The problem is not only in the U.S. ▪ Evolution of ransomware to include triggering data breaches
  • 16. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Database Security Vulnerabilities • Weak passwords • Shared passwords • Default system passwords and settings • Excessive and elevated privileges • Lack of pre-deployment security testing • Poor data encryption • Insecure database backups • Unnecessary database features
  • 17. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Protecting Sensitive Data • External threats • Direct attacks • Malware infection • Internal threats • Accidental misuse of data • Intentional data misuse
  • 18. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. External Threats to Sensitive Data • External threats • Direct attacks using compromised credentials and network vulnerability • Malware infection delivered through phishing emails or other methods
  • 19. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Internal Threats to Sensitive Data • Internal threats • Accidental misuse of data due to lack of training or human error • Intentional misuse using unauthorized access or elevated privileges
  • 20. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. •Geographic location or jurisdiction of data owners •Type of data under consideration •Industry or market sector in which the data is used Factors Affecting Data Privacy Regulations
  • 21. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Geographic Location or Jurisdiction of Data Owners • General Data Protection Regulation - GDPR • Brazilian General Data Protection - LGPD • New Zealand Privacy Bill • California Consumer Privacy Act - CCPA
  • 22. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. The California Consumer Privacy Act CCPA The California Consumer Privacy Act gives consumers more control over the personal information that businesses collect about them. • The right to know about the personal information a business collects about them and how it is used and shared • The right to delete personal information collected from them (with some exceptions) • The right to opt-out of the sale of their personal information • The right to non-discrimination for exercising their CCPA rights
  • 23. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Which Businesses Does CCPA Affect? Businesses need to follow CCPA guidelines if they meet one of these criteria: ▪ Have $25 million or more in annual revenue; ▪ Possess the personal data of more than 50,000 consumers, households, or devices; ▪ Earn more than half of its annual revenue selling consumers’ personal data. Businesses are exempt from CCPA regulations if they are in the following market sectors: ▪ Health providers and insurers already under HIPAA guidelines; ▪ Banks and financial companies covered by Gramm-Leach- Bliley; ▪ Credit reporting agencies operating under the Fair Credit Reporting Act.
  • 24. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Type of Data or Industry • Personally Identifiable Information (PII) • Health-related information - HIPAA • Financial disclosure information - SOX • Credit card payment information - PCI
  • 25. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 25 The Effects of Covid-19 on Regulatory Compliance ▪ Remote work locations ▪ Local copies of sensitive data ▪ Additional security vulnerabilities that need to be tested ▪ New protocols put in place to address compliance gaps
  • 26. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Inside GDPR
  • 27. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. GDPR Data Protection Principles 1. Lawfulness, fairness, transparency 2. Purpose limitation 3. Data minimization 4. Accuracy 5. Storage limitation 6. Integrity and confidentiality 7. Accountability
  • 28. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. GDPR - When You Can Process Data 1. With unambiguous consent from the data owner 2. When entering into a contract with the data owner 3. To comply with legal obligations 4. To save someone’s life 5. To perform a task in the pubic interest 6. With a legitimate interest
  • 29. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. GDPR - Checklist for U.S. Companies • Audit your environment for EU personal data • Inform customers why you are processing their data • Assess and improve data processing activities • Maintain data processing agreements with vendors • Appoint a data protection officer if necessary • Designate a representative in the EU • Understand the responsibilities in the event of a data breach • Comply with cross-border data transfer laws
  • 30. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Compliance Audits A compliance audit tests the state of your systems against a set of regulatory standards. Audits can be carried out by: • Internal teams • External agencies
  • 31. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Demonstrating Compliance • Proof! • Reports • Run books • Documentation • Configuration settings • Security settings
  • 32. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Why Compliance is Important • Attract business by demonstrating compliance with industry specific regulations like PCI or SOX. • Assure customers that their data is protected in your company’s databases. • Avoid financial penalties levied by regulatory agencies • Maintain a high level of customer confidence
  • 33. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Keys to Regulatory Compliance •Understanding the specific regulations that apply to your systems •Buy-in and full support from senior management •Implementing risk assessment measures for internal controls •Written procedures and policies to deal with business practices •Extensive training for management, employees and contractors •An oversight team to enforce, monitor, audit and respond to allegations and misconduct
  • 34. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Dangers of Lax Security • Data breaches • System outages • Loss of customer trust • Inability to comply with privacy regulations
  • 35. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. Dangers of Noncompliance • Loss of customer trust • Loss of business opportunities • Financial penalties
  • 36. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. IDERA Solutions for SQL Server SQL Secure SQL Compliance Manger
  • 37. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. SQL Secure Take full control of SQL Server permissions • Identify existing vulnerabilities in your SQL Server, Azure, and Amazon environments. • Harden security policies across SQL Server, Azure, and Amazon SQL databases. • Rank security levels with the security report card. • Analyze and report on user permissions across database objects. • Comply with audits using customizable templates for PCI, HIPAA and more.
  • 38. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. SQL Compliance Manager Monitor, audit and alert on SQL Server user activity and data changes • Track and manage SQL Server database compliance quickly and easily. • Audit servers, databases, and sensitive data to see who did what. when, where, and how. • Monitor and alert on suspicious activity to detect and track potential problems. • Satisfy audits with configurations and reports for multiple regulatory guidelines requirements. • Reduce impact on audited servers via a lightweight data collection mechanism.
  • 39. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. A Powerful Combination of Software Tools for SQL Server SQL Secure enables you to identify where sensitive data resides and helps you tighten up the security of your SQL Servers. It provides the functionality needed to meet data privacy regulations and keep personal data safe. SQL Compliance Manager performs the complimentary task of demonstrating compliance with the regulatory security standards that affect the data in your SQL Servers.
  • 40. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 40 THANKS! Any questions? You can find me at: @robert.agar@idera.com
  • 41. © 2016 IDERA, Inc. All rights reserved. Proprietary and confidential.© 2020 IDERA, Inc. All rights reserved. 41 There icons are editable shapes. This means that you can: ● Resize them without losing quality. ● Change fill color and opacity. ● Change line color, width and style. Examples: