Where is the sensitive data stored?Enrique Almohalla
We have our Sensitive Data Inventory document. But our mission now is finding out where this data is stored, regardless of the database technology. This means we have to go through all data models within the project scope and find out which fields in which tables store one type or another of sensitive data.
During the past few days we have done the following:
- We have connected icaria Mirage to every database within the project scope, and imported the meta model
- We have launched what we call a static analysis, which means we have searched for name patterns in fields and tables names
- We have launched a dynamic analysis. This is a set of agents specialized in finding specific information. Every agent will examine the value of a certain number of random rows of every field of every table, and report if it matches any sensitive data pattern
Image. Static analysis
Image. Dynamic analysis
We sent the results in Excel format to the client team. They really appreciated the information. Now most of the sensitive data is located.
But they’ve come up with some issues. The legacy systems store some data in a very particular way. We need to adapt our tools: agents, and probably data masking algorithms.