Database Security and Monitoring with IBM Guardium and Northdoor
Whether your organisation wants to improve security for on-premises databases or deploy a full hybrid-cloud cybersecurity environment, IBM Gold Partner Northdoor combines technical expertise with business experience.
As a recognised expert in designing and deploying database-protection solutions, in this case study, Northdoor helped a retail and corporate banking unit of one of the largest financial services companies in Japan to implement IBM Guardium Database Activity Monitor.
More information about the challenges faced, the solution implemented, and the benefits produced from the case study, which was originally published on Northdoor’s website, can be found below.
To request more information on how Northdoor can help your organisation support your IT security project, please submit the form at the bottom of this page.
The Challenge:
The bank was finding that native logging on production Oracle and SQL databases was impacting system performance and user experience. Alongside this, the existing monitoring solution was not flexible and lacked scalability.
Other challenges included:
- No defined monitoring policy and incident handling processes
- Audit reports run overnight with no real-time monitoring capability
- Limited available resources in the internal security team
The Northdoor Solution:
Northdoor implemented IBM Guardium Database Activity Monitor to provide real-time policy-based reporting.
The solution also enabled:
- The provision of 100% visibility of all database activity, including local DBA access
- Built-in reports customised to meet specific audit points
- Compliance and internal audit readiness
- All privileged user activity to be correlated to an internal change record or password release request
- Automated reporting and alerting to now be within internal incident management system
Benefits of the Northdoor and IBM Guardium Solution:
- Separation of duties with logs held in a tamper-proof repository
- No application changes were needed and minimal impact was reported on database performance
- Integration with existing TSM backup infrastructure
- Guardium software (STAP) is now part of an internal database host build to ensure global policies are enforced on new data sources in the enterprise
- Scalable architecture model (Collector, Aggregator and Central Policy Manager) to accommodate business growth and new database instances
- Granular policies implemented with monitoring and auditing to provide Who, What, When and How of all access to structured information





