Topic(s):   Security

August 15, 2007

DBA Activity results in Class Action Lawsuit
Posted by Scott Hayes @ 10:44 PM ET | Aug 15, 2007

I suppose it was just a matter of time. In a news release announced today, Girard Gibbs LLP has announced a class action lawsuit against Certegy. 8.5 million consumers are impacted.


"The complaint alleges that Certegy and FIS failed to implement and maintain adequate security measures to protect consumers’ confidential financial and personal information. Their failure to properly monitor and supervise their employee subjected consumers to risk of data theft and other fraudulent actions."

Also, "The complaint alleges that a senior database administrator misappropriated the confidential information of millions of consumers and then sold the data to direct marketing firms and data brokers who may have resold it to others."

In an earlier blog post, DB2 Magazine Editor Kim Moutsos asked "Is anyone getting information security right?"

Perhaps there are a few organizations getting it right, but these are probably the exception to the norm. Information security is a "cost" that conflicts with "profitability". Meanwhile, the data buffets are still open to vast populations of internal users who are not held accountable for their use or abuse of data privileges. It's much easier to commit data crimes when no one is watching, or auditing, database activities. Read my open letter to Oprah Winfrey for more details on information security history and the data buffet.

At the Gartner IT Security Summit, I spoke with several State CISO's about their data security initiatives. Unfortunately, they all told a sad tale about how difficult it was to get approval for data security projects. They are in good company, for private sector security executives told me similar tales of woe. It seems that only when the cost of security initiatives is actually substantially less than the costs of legal actions (albeit SOX compliance or the threat of class action lawsuits), then maybe organizations will create budget to fund the lesser security expense. This is quite unfortunate for all of us.

I spent about $250K on credit cards last year thanks to business and personal expenses. I'll confess I'm a "loyalty points and miles whore". News like this makes me think about switching to the anonymity of cash, but I imagine I'll still be over exposed by my bank and mortgage company. One thing you can do is to post a free fraud alert with the credit reporting companies; instructions on how to do this are detailed in my DBI blog.

To wrap up, I'll close with a question--- In the wake of weekly data breaches and lawsuits like this, are organizations ready to get serious about auditing database activity?

Well, one more thought. I think it stinks that an industry of so many professional good DBA people are now tarnished and branded as "privileged insider threats". At least with database auditing active, it should be possible to prove that it wasn't you that misappropriated valuable data. Surveillance works both ways.

With kindest regards,
Scott

Scott Hayes
President & CEO, DBI
IBM GOLD Consultant
Easy and Accurate Database Auditing solution for IBM DB2 LUW and Oracle: www.Brother-WatchDog.com

Trackback Pings

TrackBack URL for this entry:
http://www.ibmdatabasemag.com/blog/main/archives/2007/08/dba_activity_re.html

« DB2 LUW Performance: Progress Review plus Closing Files | Main | InformationWeek IT Salary Survey: Data management pays »





This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.



CAREER CENTER
Ready to take that job and shove it?
SEARCH JOBS
RECENT JOB POSTINGS
CAREER NEWS
10 Search Engines You Don't Know About
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Subscribe to the new digital version of IBM Database Magazine
New Digital Version

Sponsored links:



Subscribe to the IBM Database Magazine Newsletter

Email Address *
First Name
Last Name
HTML Preference
HTML Text
 

Fields with * are required.

 




Visit these other IBM and TechWeb Partner Sites: :
Maximizing ROI Through Business Process Management (BPM) and Service-Oriented Architecture (SOA)
Internet Evolution – The Macrosite for News, Analysis, & Opinion About the Future of the Internet
Business Innovation – Technology Strategies and Solutions for Driving Business Success