|
|
To combat data theft, traditional best practices have emphasized the integrity of server- resident data assets. These are the classic layered defenses built on rigorous user authentication, server-level access control, encryption, and content inspection for information in transit. While these technologies remain important, read-only activity is not logged or audited in any useful way. Furthermore, these tools cannot distinguish among authorized users conducting legitimate business, incompetent insiders bypassing corporate security policies, or intruders hijacking user identities to steal information. In short, none are well suited to the task of reliably detecting and containing breach events in real time. The best defense against illegitimate access by authenticated users is a data auditing and protection system that statistically profiles each user's access behavior on a dynamic or "rolling" basis, automatically detects anomalous activity, records forensic details about each action, and raises real-time alerts in response. By providing all of these capabilities in a transparent, passive, and pervasive system that monitors data assets across the enterprise, Tizor Mantra constitutes the modern standard for data breach risk mitigation and informed notification. Reprinted with Permission from Tizor Mantra |
|