Data privacy and security
Home > Ask the Data Management Experts > Governance, risk and compliance Questions & Answers > Business intelligence security considerations
Ask The Data Management Expert: Questions & Answers
EMAIL THIS

Business intelligence security considerations

William McKnight EXPERT RESPONSE FROM: William McKnight

Pose a Question
Other Data Management Categories
Meet all Data Management Experts
Become an Expert for this site


Tips, expert advice and sample chapters
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 09 May 2007
What are the most important components to consider in business intelligence security?

>
EXPERT RESPONSE
When it comes to business intelligence (BI) security, there are two questions to consider:

  • Who should get access to what?
  • Can those pofiles be grouped into standard profiles?

My suggestion is to start with group profiling before doing any individual profiling. Also, there are some decisions to be made are around what should the profiles be able to do to the information -- specifically insert/update. Usually, if BI is running against a data warehouse, it is read-only, with some minor exceptions.

As for access to data, except for highly sensitive items like salary (which has highly restrictive access), and unless there is significant downside to an employee having read access to the information, it would usually be granted at the database level. I've seen many redundant and inefficient architectures that divided up data across boxes, just because of the security issue when, in fact, security can be granted at table, view, row and column level. Therefore, even in the largest of BI implementations, only a handful of profiles ever need to be created. It is a problem, but someone(s), namely in IT, will need have access to all information. There is some atest software, however, that has a fix to this where the data is encrypted, even to IT administrators. As for timing, I like to make sure the users are trained before granting access. This forces necessary rigor and saves the build team a lot of headaches later.

More business intelligence security resources


Sound Off! -   Be the first to post a message to Sound Off!


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Governance, risk and compliance
Chief Compliance Officer: Top three responsibilities of a CCO
GRC tools for business intelligence security
Sarbanes-Oxley compliance: GRC technology vs. spreadsheets
Data governance software: The truth about "one-size-fits-all" data governance "solutions"

Business intelligence and analytics
Data warehousing, data mining and data querying: Terms and definitions
Business intelligence career through Web development
Do you need managed reporting tools and business intelligence (BI) tools?
How to transition to real-time business intelligence and data warehousing
Business intelligence information management (BIIM) vs. BI
Application design for OLAP servers: Considerations and advice
Operational data store vs. operational business intelligence
Can data mining expertise help my career?
Data mining in the healthcare industry
Business intelligence analyst career advice

Data privacy and security
Risk management surpasses compliance as top GRC priority
Database management: How to protect your electronic security systems
Information assurance: Dependability and security of networked information systems
IBM to buy Princeton Softech for data management, archiving and classification
Database activity monitoring helps USEC with SOX compliance
Data leakage could be caused by messaging technology
IBM plans acquisition of Consul Risk Management
Data breach costs rise, drive security spending
Data governance trends, with expert Gwen Thomas
Insider security threats: Watch out for the quiet ones

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
consumer privacy  (SearchDataManagement.com)
Patriot Act  (SearchDataManagement.com)
privacy  (SearchDataManagement.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2005 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts