SHARE
Facebook X Pinterest WhatsApp

Errors in Database Account Provisioning Can Lead to Major Breaches

Feb 9, 2010

Some of the greatest threats to databases come not through hackers, dangerous as they are, but instead through account-provisioning errors, such as old accounts that are still able to be accessed and through which information can be stolen. Unfortunately, in many organizations the process of database account provisioning and validation never quite happens. Even if a company has a form of identity and access management tool, database accounts sometimes never get worked in because of their integration complexity. Consequently if accounts are tracked it is done manually which often leads to the number of accounts or who has access being unknown. Pooled application accounts can complicate matters even more since user identity can be lost when web applications access a database.

To begin, organizations with database account provisioning problems can begin to correct things by finding out:

  • Where accounts are and everything they’re used for
  • When the passwords to these accounts were last changed
  • What access control list system is being used and when it was last checked
  • If the audit logs the databases generate are being analyzed.

Additional steps include such things like native database logging, log management, security information, and event management tools etc. to make sure accounts are properly provisioned and not abused. Though there has to be some sort of logging mechanism, it’s not always enough, but it’s a start into tracking users and their access of information.

Recommended for you...

Best Certifications for Database Administrators
Ronnie Payne
Oct 14, 2022
Become More Efficient at Writing TSQL by Creating Code Snippets
Gregory Larsen
Jun 30, 2021
Line Numbers in SQL Server Management Studio
Gregory Larsen
Sep 4, 2018
Couchbase Raises $60 Million to Fuel NoSQL Database Efforts
Sean Kerner
Jun 30, 2014
Database Journal Logo

DatabaseJournal.com publishes relevant, up-to-date and pragmatic articles on the use of database hardware and management tools and serves as a forum for professional knowledge about proprietary, open source and cloud-based databases--foundational technology for all IT systems. We publish insightful articles about new products, best practices and trends; readers help each other out on various database questions and problems. Database management systems (DBMS) and database security processes are also key areas of focus at DatabaseJournal.com.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.