IBM Security Guardium Data Protection Other Advice
My organization has two teams using IBM Guardium Data Protection. One is an analyst team that looks after the solution, and the other is the SOC team in charge of monitoring events on IBM Guardium Data Protection.
There's a team of five people in my organization that takes care of deploying the policies, and there's a team of twelve analysts that does the monitoring of events in all monitoring solutions used in the company, aside from IBM Guardium Data Protection events.
Currently, the solution isn't being used to its full extent because it's still in the testing phase, and my organization is still new to the solution, so it has to check on the capabilities of IBM Guardium Data Protection and how it works. Users within my company still have to learn how to aggregate, how to send logs, which security tools to monitor, etc. The solution is still in the evaluation phase within the company, and there's still a need to check its performance and analyze its features.
My advice to others looking into implementing IBM Guardium Data Protection is to first get familiar with the solution and compare it with other solutions. IBM Guardium Data Protection is a market leader, so I recommend that you deploy it or purchase it for the purpose of database security. It's a well-known product.
I'm rating IBM Guardium Data Protection eight out of ten.
My company is a customer of IBM Guardium Data Protection, with no IBM partnership.
View full review »I rate Guardium nine out of 10 overall. I rate Guardium 10 out of 10 for data activity monitoring and nine for vulnerability assessment. It's easy to implement and does its job. But I would rate it seven out of 10 in terms of advanced features.
My advice to prospective users is to have a proper source to deploy it in your environment, or you're wasting money. The second thing is to know precisely what you want from Guardium. Is it DAM, VA, or are you going further? In terms of security posture, those lines should be clear.
View full review »I think third-party application integration is supposed to be an integral part of IBM without any cost, so IBM should consider that.
I would rate this solution an eight out of ten.
View full review »
Buyer's Guide
IBM Security Guardium Data Protection
March 2024
Learn what your peers think about IBM Security Guardium Data Protection. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,740 professionals have used our research since 2012.
I recommend this solution and rate it nine out of 10.
View full review »I don't feel that our local partners are fully equipped with the technical knowledge of the product. Whenever we need support that requires technical expertise, we go to the IBM support portal. As a result, we experience time delays in terms of support and it would be helpful if the local partner improved their knowledge. The other option would be for IBM to provide some management training for the on-prem engineers.
I rate the solution five out of 10.
View full review »DL
Dr. Sajid Latif
Public Sector Specialist at Interactive Group
I recommend IBM Security Guardium Data Protection to others and rate it an eight out of ten. It is a very good enterprise-grade solution.
I would rate it an eight out of 10. To make it a 10 they would need to do streamlining of some of the agent features, some of the patches, make it a little bit more user-friendly on the documentation.
In terms of advice, I would make sure you do a thorough PoC, that you join the virtual user group that meets once a month, as well as a customer user group that IBM is not involved in, where you can also get some candid questions and answers.
View full review »Since I have not implemented the product yet, I would give it an average rating. Overall, I rate the product an eight out of ten.
View full review »We use IBM Guardium Data Protection for our databases. I can't remember the version we're currently using.
I don't think IBM Guardium Data Protection charges you based on the number of users, e.g. they charge based on the number of licenses, and it's either on a per-license or a per-data basis, so I cannot give the number of users currently using the application.
Increasing the usage of IBM Guardium Data Protection depends on the budget. Nobody wants to increase costs, but costs are increasing, so I don't think we plan on increasing usage for the application.
For the deployment of the application, we have the OEM and our technical team in charge.
I'm giving IBM Guardium Data Protection a rating of nine out of ten.
View full review »It is the only solution that can meet the needs of both internal and external audits. It's a very powerful tool that can solve a lot of audit needs.
Overall, I rate IBM Security Guardium Data Protection ten out of ten.
DC
Darren Chaker
Operator at Halliburton
Put simply, human error is often the downfall of computer security. When using IBM Guardium, or any encryption software for that matter, use common sense: Encrypt data when not in use, watch where you enter in passwords (not at Starbucks in view of security cameras that can be retrieved by an adversary, or the person next to you), and watch out not to inadvertently install spyware while clicking on a random link.
View full review »MW
reviewer1633014
DBA at a manufacturing company with 10,001+ employees
If I were choosing a solution now, I would probably look at Imperva and Insights, and go the agentless route, rather than deal with collectors. They still have them with the new system, but they're a little lighter weight. From a manageability perspective, from a scalability perspective, in terms of supporting model databases, they seem to be more viable solutions moving forward.
I rate this solution an eight out of 10.
View full review »While working with the solution, you have to be clear about your requirements. The solution offers different pricing based on different functionalities. If you are able to identify your requirements properly, you are going to do well with the price and get the best out of the product. So understanding the requirements is very important. I would rate this product 8 out of 10.
View full review »VT
Viswanath Tharigonda
Inforomatica tech lead at a tech vendor with 10,001+ employees
This tool works very well with IBM products but not so well with other tools.
I rate the solution six out of 10.
KA
Khaled AlKadi
Sales Director at Jordan Business Systems
I recommend this solution to medium and big companies. Small customers do not need to maintain it a lot. The price and value they will get from it are worth it, especially if they need to monitor many databases and manage their environment. Guardium can help them see who accesses the databases to prevent data breaches and monitor the audit trail. Smaller companies with one or two databases can manage them by themselves, but Guardium becomes more valuable as the size of their databases and the number of users grow.
Overall, I rate the solution a ten out of ten.
Try to have a dedicated team. There are a lot of moving parts and you need take a hands-on approach. It doesn’t come configured out of the box.
View full review »I would definitely recommend it. It's easy to use and it can save a lot of headaches, by just implementing it and being able to ask at the time of audit. When it comes to audits, every company wants to be safe.
View full review »BD
reviewer841896
Information Security Analyst Consultant at a insurance company with 10,001+ employees
Most important criteria when selecting a vendor:
- The ability to meet requirements.
- Costing
- Scalability and market share.
SW
Suhail Wagle
Sr. Network Specialist at a tech services company with 501-1,000 employees
If you are considering IBM Guardian Data Protection you should be aware of your environment. For example, if you are in the banking sector you need to plan very well so it can be scaled accordingly.
It is important to hire a consultant when installing this solution. They can provide an analysis of what exactly needs to be done. Keep in mind that this is a data access management database, it's not only about data but also about files.
I rate this solution a 9 out of 10.
View full review »If you are looking to implement Guardium, you first need to understand your requirements. The objective of these database and security monitoring solutions is for compliance and auditing. You want a solution that will monitor everything, but the main objective is to monitor the right areas or the key parts of the area that should be monitored. This is the one thing customers should consider before choosing any database or similar solution.
We have good relationships with our customers, so whenever they're looking for a solution, we try to partner with them and align them with a product that will meet their needs. Usually when we go with this product, we go with SQL first, then go for integration deployment. Our recommendations are based on customer requirements. Even if it's a good product, it may not be a good fit for the customer.
I would rate this product an eight out of ten, just because there's always room for improvement.
View full review »BH
reviewer1458435
DBA Dept. Manager at a computer software company with 501-1,000 employees
We may be using version 11 of the product at this time.
We're still in the process of implementing the solution. It's still quite new to us.
Right now, I would rate the solution at a nine out of ten, however, I do need more time to really get to know it to evaluate it properly. I likely need another good six months or so with the solution before I can really rate it effectively.
View full review »We're looking to upgrade the solution soon. I'm not sure which version we are currently using.
I would recommend others considering the solution to make sure they get local partners who can basically deploy the product. They need to have someone with sound experience. I have found a partner who applies the product often just simply deploys it and they don't have a use case available. They don't have the right experience. You need to choose your partner carefully or be ready to work hard yourself to deploy the product in the best possible way.
I would rate the solution seven out of ten.
View full review »When selecting a vendor, what's important for us is
- how quickly they can provide customer support
- scalability
- reliability
- dependency.
Overall, I'd rate it at eight out of 10. It could be a 10, however there are few features, like the ones I mentioned, that are still a work in progress.
Regarding advice to a colleague, determine what your business needs are. If your business needs are similar to the ones Guardium solves then you should go for it. The implementation is seamless, the requirements are straightforward, and it's easy to use the product.
View full review »I give it a nine out of 10. It's not perfect: Issues like using a high CPU and, in the beginning, it was a little unclear on how to install it. This is only on the mainframe side.
In terms of advice, do a good PoC on it, because I believe it's a very expensive solution. And it has to satisfy the auditors, for sure. If it doesn't satisfy the auditors it won't go anywhere.
RM
reviewer1161831
Senior Analyst at a energy/utilities company with 10,001+ employees
Personally, I would not recommend this product.
If you have complicated report requirements which involves very specific filtering and/or aggregation. And you have lots of resources in your virtual platform. Then give it a try.
Also I suggest you take a look at other top grade product like Imperva SecureShere. the reduction in resource requirements is 3 times less and it have plenty of nice features out of the box.
View full review »VN
Velly Nusmir
Senior Manager at PT Permata Anugerah Abadi
I recommend IBM Security Guardium Data Protection and rate it a nine out of ten.
View full review »AF
AhmedFattah
CyberSecurity Leader Specialist at KLNCIT
I rate IBM Guardium Data Protection 10 out of 10. Anyone can understand this product.
AA
AppMainfaf77
App Mainframe And Storage at a financial services firm with 1,001-5,000 employees
In terms of advice, I would say allow the technology to mature a little more. I think we were one of the first, if not the first, to implement Guardium. And, like I said before, it was kind of painful, but let the maturation process run it's course. I'd say learn from other people's mistakes or, not so much mistakes, just experiences. Benefit from other peoples' pain, bumps, and bruises.
I rate it seven out of 10 only because it's a unique, niche offering that is not, that I know of, offered elsewhere in the marketplace. It fills a need, which is good. I don't know how prevalent the need is in the marketplace but it's nice to have an offering there that, when needed, you can implement something.
View full review »vast product as there are many features of this product to full fill the customer requirements, and less expertise are the there worldwide.
View full review »MH
mehrab hussain
Junior Software Engineer at a computer software company with 201-500 employees
IBM, in general, is the best. I would recommend this solution to others.
I am not familiar with other products. I only know IBM Guardium.
I would rate IBM Guardium Data Protection a nine out of ten.
View full review »Most important criteria when selecting a vendor: At the end of the day, it would have to be the support and relationship. There are a lot of smart people out there building products which do things. However, not everyone can use them, and without having someone to call, it is sort of its own disadvantage.
View full review »Our most important criteria when selecting a vendor are stability and architecture.
I rate this solution a nine out of 10 because there are a few things I'm working through that I would like to see improved, mostly around the stability on the agent software side, working with the database vendors.
Regarding advice, I would recommend you use it and that you try to leverage IBM's support and services as much as possible to help get through the initial installation and configuration.
View full review »If it's the vendor or a third-party telling you how things should be set up out of the gate, go with that and don't argue with them. That saves a lot of time.
I would rate it a nine out of 10. It has done a really good job for us.
View full review »QN
Quan Ngo
Sales leader at EFH
I would rate IBM Security Guardium Data Protection an eight out of ten.
View full review »I can definitely recommend IBM Guardium and we are going to continue using and promoting it in the future.
I have been working with IBM for approximately 13 years and I've personally found that IBM products are very useful. However, the problem is that IBM's product stack isn't fully present in this country and there is a clear lack of industry resources, so customers remain unaware of their products and they are not adopting products even though this product is very good. Whenever we are talking about the idea of data protection we talk about IBM's solution, Guardium Data Protection.
The main problem is that customers often throw questions like, "What about deployment? What about the support? Are we going to get good support from the local team?" They're not bothered about portal support, they talk about the internal market industry resources. That's where we come in. So even though I am recommending IBM, I know some customers will also like Oracle AVDF.
I would rate IBM Guardium Data Protection an eight out of ten.
View full review »VD
Victor Díaz Bañales
Socio Director at RAMDIA
We would recommend this solution to others. It is a good solution at a good price, and your data is invaluable.
I would rate IBM Guardium Data Protection a nine out of ten.
View full review »AV
AjaiVictoria
Information Technology Consultant at Aeries Technology Group
From my experience, I find that IBM Guardium is pretty good and I would recommend it.
The monitoring and analytics capabilities make it a very good product, although we have had intermittent problems with our database connectors so it is not perfect.
I would rate this solution a nine out of ten.
View full review »I would rate this solution six out of 10. The benefit to the cost is not justified, in my opinion.
I would say Guardium is a good product. It's a very good product, but you want to weigh how much you want to implement. Do you want to focus on only certain applications? Certain databases? Don't do it across the enterprise. So think about that.
I would consider IBM brand value.
View full review »SK
reviewer1290021
VP - Enterprise Security & Cloud Business at a tech vendor with 1,001-5,000 employees
This is one of the core applications for customers and is not something like an endpoint security or perimeter security. It's a specialized use case. This is a textured product and the brand equity of IBM means it's reliable. I have long-term relationships with my clients and wouldn't like to deploy something that gives me problems. This is a good product.
I would rate this solution an eight out of 10.
View full review »MT
Databasefec0
Database Administrator at a healthcare company with 10,001+ employees
IBM Guardium is good.
Most important criteria when selecting a vendor: reliability.
View full review »MN
Securead44
Trusted Security Advisor at a tech services company with 501-1,000 employees
When it comes to implementing this solution, it is important for people to know exactly what they need to do. This includes what they need to monitor, what they need to protect, and what kinds of queries they want to prevent. They shouldn't rely on having this tool teach them what they need to do.
Next, people need to make sure that they are getting proper support. This can be from the vendor, by having an advanced SLA for example, or a strong local partner to help them. If they have any trouble, especially something urgent, then they want to have this support in place.
The third thing is to have somebody who is trained to take care of the system. Assuming that it is easy and that anybody can handle it will be the start of a larger problem. It will not seem too much at the beginning, but after a year they will be unhappy with the product.
It is important to recognize that there are several milestones for any Guardium project. Our consultant, for example, is an expert in that domain. He usually submits a project plan showing the implementation stages for the project. There are prerequisites that have to be put in place and verified, then Guardium deployed on the server. This can be either a physical or virtual server. Then the database configuration begins, which is followed by the fine-tuning phase. Finally, all of the appropriate documentation for these aspects has to be compiled. The length of time required for all of this depends on the requirements.
I would rate this solution an eight out of ten.
View full review »Buy services. You do not need to have services for the entire implementation, but, at a minimum, invest in the Quickstart option to get up and running and to provide knowledge transfer. Once Guardium is installed on a few systems, it is very easy to add and manage.
View full review »You need to know what you want to protect very well.
View full review »It does a good job for what it's designed to do. You may want to look into the enhanced reporting that's available by the third party, because some of the report-building features are not as nice as some of the third party's.
View full review »At first, IBM Guardium may seem complicated, but once you learn the basics, it becomes simple to use.
View full review »There are a lot of things that could be better, but it is performing pretty well.
Take your time and learn each step. Make sure that you understand each step, because if you miss something, it will come back. Then, you have to circle back and figure it out anyway.
Most important criteria when selecting a vendor:
- Price
- Support
- Reliability in the marketplace
- Integration with other systems.
Overall, it is a very solid product.
View full review »We're very happy with it. It depends on what your needs are, but it meets our needs.
View full review »There are three main steps when implementing a Data Activity Monitor (DAM) solution.
- Discover and Classify: Find your databases in your environment, and decide which one of them has confidential data that you need to monitor. Classify your data in your database if it includes critical data like personal ID, credit card, or IMEI numbers.
- Monitor Activities: Monitor all end-user activities while developing your policy rules and critical activities.
- Block Critical Activities: Define and block critical activities to prevent data leakage.
Take your time. Think about the elements you want to audit. Don't just audit everything. Understand the normal traffic, so you can focus on the abnormal traffic.
View full review »FT
Farhan Tariq
Information Security Analyst at a government with 1,001-5,000 employees
If you have enough budget for database security, you must evaluate this product for your use cases.
View full review »CR
reviewer1830612
Head, Cybersecurity at a tech services company with 11-50 employees
I would give Guardium a rating of eight out of ten.
View full review »ND
reviewer1131528
Technical Manager at a computer software company with 51-200 employees
I rate IBM Guardium Data Protection a seven out of ten.
View full review »I would rate it an eight out of 10 because it is very stable; we had some problems but they were solved, and we can do what we need to do.
View full review »This product could by easily used with other security products; for example, SIEM products such as IBM QRadar and ArcSight.
View full review »MS
reviewer1681524
Security Specialist at a tech services company with 51-200 employees
I rate IBM Guardium nine out of 10. I would absolutely recommend the solution to others.
View full review »MS
reviewer1681527
Security Specialist at a tech services company with 51-200 employees
I would recommend this solution to others.
I rate IBM Guardium Data Protection a nine out of ten.
View full review »SM
Sidney Monteiro
Information Security Analyst at a tech services company with 501-1,000 employees
- Read important articles related to DAP such as the "2017 Planning Guide for Security and Risk Management."
- Gather information from the servers (operating system with version and database types with the versions) of the environment to be monitored.
- Check which DAP solutions can monitor the environment.
- List the “mandatory requirements” and “non-mandatory requirements.” It is important to have in mind which points will be evaluated.
- Request PoCs with the main DAP manufacturers (IBM, Imperva, and Oracle).
- Do the sizing with the topology to get an idea of the requirements and cost of the project.
Most important criteria when choosing to partner with a company: I started working with IBM only one year back. When I started a partnership with them, IBM had the security portfolio which covered most of the region where my customers were. IBM has a name with the support along the quality of its products.
View full review »When selecting a vendor, I look at the price and the scope of solution.
My advice is to use this solution. For security and compliance it is very, very good.
View full review »EW
Wainai2
IT Security Analyst at a tech services company with 11-50 employees
I would give the product a score of eight out of 10. This is due to its deep level of granularity and guided process/audit workflow generation.
View full review »Buy it.
View full review »Take care of the scope and the monitoring mode. Also, if the size of the DB is high then do not do it over virtual.
View full review »TA
reviewer1360929
Information Security Consultant at a tech services company with 51-200 employees
My advice to anybody who is implementing this solution is to start small, with a test environment, and then scale it up. This way, if there is a fault at the beginning then it won't be multiplied by the time you have a larger deployment and are fully integrated. In this way, you will see if it meets the requirements.
Overall, this is a wonderful product.
I would rate this solution an eight out of ten.
View full review »Ask for a PoC project and then decide.
View full review »VG
reviewer933939
Security Engineer at a tech services company with 501-1,000 employees
Guardiam's accountability is good - by design, it doesn't give any root privilege to customers, which means we don't have highly important privilege for access to Guardiam. They use only a user level, so kernel-level users are prohibited, which means there aren't any accidental effects from the customer side. I would rate this solution as eight out of ten.
View full review »Buyer's Guide
IBM Security Guardium Data Protection
March 2024
Learn what your peers think about IBM Security Guardium Data Protection. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,740 professionals have used our research since 2012.