Elnion
No Result
View All Result
Thursday, September 17, 2026
  • Login
  • AI
  • Cloud
  • Data
  • Digital Enterprise
  • Telco & Mobile
  • Cyber Security
  • Infrastructure
  • Automation
  • Supply Chain
Subscribe
Elnion
  • AI
  • Cloud
  • Data
  • Digital Enterprise
  • Telco & Mobile
  • Cyber Security
  • Infrastructure
  • Automation
  • Supply Chain
No Result
View All Result
Elnion
No Result
View All Result
Home Data

Handling Today’s Most Important Data Management Issue

by Craig Mullins
November 17, 2024
in Data, Data Warehouse, Digital Enterprise, Privacy, Security
0
Share on TwitterShare on LinkedInShare on Facebook

Although there are many important issues facing organizations as they work to manage and benefit from data, without a doubt the most critical issue facing data management is data privacy and security. With the increasing reliance on digital systems and the proliferation of sensitive data, organizations face significant challenges in protecting their databases from unauthorized access, data breaches, and cyber threats.

This challenge is amplified by increasingly strict regulatory frameworks, such as GDPR in Europe, CCPA in California, and similar regulations globally, which impose stringent requirements for data protection and user privacy.

Data Breaches

The rise in sophisticated cyberattacks places constant pressure on organizations to safeguard their data. As data volumes grow, so does the attack surface, making comprehensive data security measures essential.

Recent data breaches have highlighted vulnerabilities across various sectors, affecting millions and underscoring the importance of robust cybersecurity. In 2023, for instance, a significant breach at the U.S. Department of Education exposed sensitive information on federal student loan borrowers, raising concerns about public sector cybersecurity. Another breach at MOVEit, a widely used file transfer service, compromised the data of numerous organizations worldwide, impacting millions of individuals and companies dependent on the platform. Even global healthcare networks haven’t been spared, with data breaches affecting patients’ personal and medical records, as seen in the ransomware attack on HCA Healthcare, which exposed data for over 11 million patients. These incidents emphasize the need for stringent security measures, timely breach detection, and effective incident response strategies to minimize harm and reinforce consumer trust in data privacy and management.

Data breaches can lead to severe consequences, including financial losses, reputational damage, and legal repercussions. As a result, ensuring the security and privacy of data has become a critical concern for organizations across various industries. It involves implementing robust access control mechanisms, encryption techniques, and adopting best practices for data governance and compliance. Of course, these things are easier said than done.

Compliance and Regulatory Burdens

Regulations demand that organizations not only secure data but also provide visibility into how it’s used, stored, and shared. Compliance requires companies to invest in technologies and processes that ensure data governance, auditability, and transparency.

There are many industry and governmental regulations driving the need to improve data protection, management, and administration. One of the more visible governmental regulations is the Sarbanes-Oxley Act (SOX), officially known as the U.S. Public Accounting Reform and Investor Protection Act of 2002. The goal of SOX is to regulate corporations in order to reduce fraud and to improve disclosure and financial reporting. The impact and cost of the law on IT and database management is significant. Section 404 of SOX specifies that the CFO must guarantee the processes used to produce financial reports. Those processes are typically computer programs that access data in a database.

Control and management of personal data is a big regulatory hurdle that is increasing in significance, mostly due to GDPR. The GDPR (General Data Protection Regulation) and CCPA (California Consumer Privacy Act) are landmark data privacy regulations that impose rigorous data management standards on organizations handling personal data. GDPR, applicable to the personal data European Union citizens, requires organizations to ensure data protection by design, uphold data subject rights (such as access, rectification, and erasure), and maintain stringent data security practices, with heavy penalties for non-compliance. CCPA, focused on California residents, mandates that companies disclose data collection practices, offer opt-out options for data sales, and enable users to request data deletion. Both regulations necessitate comprehensive data governance, ensuring that organizations track, secure, and document personal data management processes to protect consumer privacy and maintain regulatory compliance.

Another significant regulation is the Health Insurance Portability and Accountability Act, commonly referred to as HIPAA. This legislation mandates that health care providers protect individual’s health care information, stating that providers must be able to document everyone who even so much as looked at their information. HIPAA audits frequently require the examination of the processes used to create, document and review exception reports and logs. When confronted with a HIPAA audit, organizations can be required to produce a list of exceptions to policy, such as, “When were patient records accessed during off hours and by whom?”  Without database auditing software, it is impossible to produce a list of users who looked at a specific row or set of rows in any database.

Other compliance related legislation includes the Gramm-Leach-Bliley (GLB) Act (also known as the Financial Modernization Act of 1999)  and the E-Government Act, passed in 2002 as a response to terrorist threats. Title III of the act is named the Federal Information Security Management Act (FISMA), which states that federal agencies, contractors, and any entity that supports them, must maintain security commensurate with potential risk.

Another significant regulation is the Payment Card Industry Data Security Standard (PCS-DSS), which is an industry standard, as opposed to the others mentioned previously which are governmental regulations. Established by the major credit card companies, PCI-DSS was established to dictate the requirements for organizations who accept payment cards. Its goal is to help prevent credit card fraud, hacking, and other security issues. Failing to comply risks losing the right to accept credit cards as payment. PCI-DSS emphasizes the importance of real time monitoring and tracking of access to cardholder data, as well as continuous assessment of security health status of the database storing the data.

Regulatory compliance holds an important sway over upper level management at most medium- to large-size organizations because of its potent impact. Business executives are keenly aware of the need to comply, although they are not always aware of all the details that involves. This is so because failure to comply can result in prosecution which may involve huge fines and even. Regulatory compliance can impose upon C-level executives the need to be able to prove that corporate data (and therefore, database systems) are protected and that processes and procedures enacted upon the data are accurate and required.

Dealing with Data Volume

As the volume of data continues to grow exponentially, another important issue is managing the scalability and performance of databases. Ensuring that data is protected, while at the same time being efficiently accessible, is a major data management challenge being faced today.

The massive influx of data from IoT, social media, and business transactions adds complexity, increasing the difficulty of protecting data.

Organizations often struggle to maintain security while ensuring data accessibility and usability for analytics. As the amount and types of data swell, identifying which data needs protection, and what types of protection, becomes more difficult.

Furthermore, the need for more and more data will not diminish any time soon, especially as data becomes more crucial for feeding AI and Machine Learning systems.

Additional Data Security Concerns

Of course, there are other important issues in terms of data security and protection including data archiving, database auditing, data access controls, encryption, data masking, and more.

Database archiving protects data by removing it from the database system and storing it for posterity in an archive data store. There are over 150 international, federal and local laws that establish the mandated retention period for different types of data. Many of these laws greatly expand the duration over which data must be retained. Many organizations deal with retention periods based on business needs only, but this can be short-sighted. Depending on the industry, what was once a short retention period may now expand into decades or even longer. To comply with these laws corporations must re-evaluate their established methods and policies for managing and retaining data. What worked in the past to retain data for a few years is no longer sufficient over a much longer period.

Database auditing refers to the process of monitoring and recording activities that occur within a database system. It involves capturing and analyzing various actions and events, such as user logins, data modifications, schema changes, and system configuration updates. The primary goal of database auditing is to ensure the integrity, security, and compliance of the database environment. You can think of it as “monitoring who did what to which data when” in the database. Database auditing should be conducted in alignment with applicable legal and privacy requirements. Organizations should define clear auditing policies, specify the scope of auditing, and ensure the appropriate level of data protection and access controls are in place to safeguard the audit logs themselves.

Data access controls are mechanisms and procedures that can be used to manage the access and usage of data within a database. These controls are designed to ensure that only authorized individuals or entities can access, modify, or retrieve specific data based on predefined permissions and security policies. Data access controls are an essential component of data security and play a crucial role in protecting sensitive information from unauthorized access, misuse, or data breaches. Examples include authentication, authorization, Role-Based Access Control (RBAC), data encyrption, and database views.

It’s important to implement a comprehensive and layered approach to data access controls, combining multiple control mechanisms to ensure the security and integrity of sensitive data. The specific access control measures implemented may vary based on the nature of the data, the system architecture, and the regulatory requirements applicable to the organization.

Another technique to protect database data is data masking, which is the process of protecting sensitive data from inappropriate visibility by replacing it with realistic, but not accurate data. The goal is for sensitive, personally identifiable information (PII) to not be exposed outside of authorized environments. Data masking can prevent fraud, identity theft, & other criminal activities. Data masking can be done while provisioning test environments so that copies created to support development & testing do not expose sensitive information. Valid production data is replaced with usable, referentially intact, but obfuscated data. After masking, the test data is usable just like production data, but the information content is secure.

And let’s not forget about another long-standing security issue, SQL injection, which is a form of web hacking whereby SQL statements are specified in the fields of a web form to cause a poorly designed application to dump database content to the attacker. In order for SQL injection to succeed, the application code used by the website must be vulnerable to an injection attack. SQL injection relies on programs that do not adequately filter for string literal escape characters embedded in SQL statements or where user input is not strongly typed. So instead of inputting data into a form, SQL statements are supplied. The SQL is “injected” from the web form into the database causing it to be executed and access (or even modify) unintended data. This form of attack has been known for decades now, but it still happens to poorly-designed applications.

The Bottom Line

As data professionals and DBAs navigate the data security and privacy issues covered above, they’re called to balance robust security with efficient data access for analytics and business intelligence. This involves implementing appropriate policies, controls, and techniques to prevent unauthorized access. Additionally, organizations need a clear data governance strategy to manage the lifecycle of data, from acquisition to disposal, while ensuring it meets regulatory and ethical standards.

Data privacy and security, therefore, isn’t just a technical challenge—it’s a business imperative that affects trust, reputation, and long-term viability.

Tags: datadata breachprivacyRegulationregulatory compliancesecurity
Craig Mullins

Craig Mullins

Craig is both President and Principal Consultant of Mullins Consulting Inc. He is an in-demand analyst, author, speaker, and practitioner, with over three decades of real world proven experience, across all facets of database systems development, including creating and teaching database classes, systems analysis and design, along with data analysis, database administration, performance management, and data modelling.

Related Posts

AI

The 80% Crisis: UK Data Leaders Warn Our Data Isn’t Ready for AI

September 5, 2026
AI

The AI Illusion: Craig S. Mullins Exposes The Hidden Costs Crippling Modern Data Architectures In His Latest Book

September 5, 2026
AI

The 80% Crisis: America’s Data Leaders Warn Our Data Isn’t Ready for AI

September 3, 2026
No Result
View All Result

Recent Posts

  • The 80% Crisis: UK Data Leaders Warn Our Data Isn’t Ready for AI
  • The AI Illusion: Craig S. Mullins Exposes The Hidden Costs Crippling Modern Data Architectures In His Latest Book
  • The 80% Crisis: America’s Data Leaders Warn Our Data Isn’t Ready for AI
  • Building No-Regret Quantum Readiness in the Mining Sector
  • The Quantum Cybersecurity Imperative: Securing the Mining Enterprise for the Future
Elnion

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Cloud
  • Data
  • Digital Enterprise
  • Telco & Mobile
  • Cyber Security
  • Infrastructure
  • Automation
  • Supply Chain

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In