I did a presentation last year for the Rochester OWASP on Database Encryption that is likely to be useful. I recommended Oracle DBMS_CRYPTO rather than the TDE, or since it isn't going to provide protection against most application level attacks.

Rochester OWASP Web site:  http://www.owasp.org/rochester
Specific presentation: http://www.owasp.org/images/c/c1/Database_Encryption.ppt

-- Ralph Durkee, CISSP, GSEC, GCIH, GSNA, GPEN
Principal Security Consultant
http://rd1.net


On 5/25/2010 10:22 AM, John Hoyt wrote:
Does anyone have experience with database (row/record) encryption? I'm looking at Oracle TDE and other competitor solutions.

Some of the main points I'm interested in are:

    * Performance
    * Key management
    * Backups
    * Comparison against full-disk encryption


Thanks for any help,
John




_______________________________________________
Pauldotcom mailing list
[email protected]
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com
_______________________________________________
Pauldotcom mailing list
[email protected]
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com

Reply via email to