it_user842892 - PeerSpot reviewer
Cyber Security Architect at a tech services company with 11-50 employees
Real User
Our clients use Accelerators to help with PCI and GDPR compliance
Pros and Cons
  • "We have integrated IBM Guardium​ with IBM Watson Curator. They access Curator to identify and correlate other actions the user is doing to determine if this is a legitimate action or not."

    What is our primary use case?

    We have implemented it on an industrial network to monitor the production of medicines. This is something that is very controlled by Brazilian regulations and we have to keep an audit trail for this data. Trying to enable it on SQL Server - that was our client's main server - the load would go so high that they couldn't use the application anymore. They are using Guardium now so they can produce that audit trail for audit compliance.

    How has it helped my organization?

    We have integrated IBM Guardium with IBM Watson Curator. They access Curator to identify and correlate other actions the user is doing to determine if this is a legitimate action or not.

    In terms of advanced features, our clients are starting to implement it on an order basis so they can get to GDPR and the like; those Accelerators. They also use it a lot for PCI, to get access to credit cards.

    Guardium has saved us time and money, mainly on the discovery process and senior management is aware of this, of course.

    What is most valuable?

    The Audit Trail.

    What needs improvement?

    They could improve the Data Masking a little.

    Buyer's Guide
    IBM Security Guardium Data Protection
    March 2024
    Learn what your peers think about IBM Security Guardium Data Protection. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
    769,630 professionals have used our research since 2012.

    What do I think about the stability of the solution?

    Stability is quite good. We had some problems, but support is very effective so we were able to solve them very quickly.

    We had instability with reports, they were giving some errors. I don't know exactly what had happened because I wasn't the one involved, but we couldn't access reports.

    How are customer service and support?

    Tech support is very good.

    Which solution did I use previously and why did I switch?

    We knew we needed to switch because of that problem with the audit trail, that SQL couldn't keep up with what we needed to do for auditing. That's why we had to search for a new solution.

    How was the initial setup?

    It's very easy.

    What other advice do I have?

    I would rate it an eight out of 10 because it is very stable; we had some problems but they were solved, and we can do what we need to do.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
    PeerSpot user
    PeerSpot user
    BI Consultant /Data Security at a tech services company with 51-200 employees
    Consultant
    You can divide roles, creating safe access zones; manage credentials; and access rules.

    What is most valuable?

    • Detailed and customizable reports with real-time alerts for the full vision of database/files activity.
    • Versatile rules for access control in real-time including blocking, masking, etc.: These rules are really helpful to fulfill enterprise security specifications. With them, you could divide roles, creating safe access zones; manage credentials; and access rules. The rules are easy to develop and customize.

    What needs improvement?

    • UI: Version 10 of Guardium was introduced with a new UI that was completely redesigned. Some fast-access functions and options are not easy to find in the new UI.
    • Real-time masking is a bit simple and doesn't allow you to create complex masking rules.

    For how long have I used the solution?

    I have about one year of hands-on experience.

    What do I think about the stability of the solution?

    I have not encountered any stability issues.

    What do I think about the scalability of the solution?

    I have not encountered any scalability issues.

    How are customer service and technical support?

    Technical support is 9/10. I participated in communication with tech support only once.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution.

    How was the initial setup?

    Initial setup is straightforward. All the commands are simple to understand. The installation guide is simple and comprehensive.

    Which other solutions did I evaluate?

    Before choosing this product, I evaluated Imperva products.

    What other advice do I have?

    This product could by easily used with other security products; for example, SIEM products such as IBM QRadar and ArcSight.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    IBM Security Guardium Data Protection
    March 2024
    Learn what your peers think about IBM Security Guardium Data Protection. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
    769,630 professionals have used our research since 2012.
    Security Specialist at a tech services company with 51-200 employees
    Real User
    Has good document protection features
    Pros and Cons
    • "Setting up Guardium was easy and straightforward."
    • "Guardium's storage capabilities could use some improvement. I'd also like to have some better integration using digital technology or a connector."

    What is most valuable?

    I like Guardium's document protection features.

    What needs improvement?

    Guardium's storage capabilities could use some improvement. I'd also like to have some better integration using digital technology or a connector.

    What do I think about the scalability of the solution?

    Guardium is scalable. I've been able to integrate it with other solutions.

    How are customer service and support?

    I have initiated tickets for various reasons, and IBM support was very good.

    How was the initial setup?

    Setting up Guardium was easy and straightforward. 

    What's my experience with pricing, setup cost, and licensing?

    It's an enterprise license.

    What other advice do I have?

    I rate IBM Guardium nine out of 10. I would absolutely recommend the solution to others.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Security Specialist at a tech services company with 51-200 employees
    Real User
    Supports many databases, scalable, and straightforward installation
    Pros and Cons
    • "The solution supports a lot of databases."

      What is our primary use case?

      We are using IBM Guardium Data Protection for activity monitoring, blocking users,  entitlement for knowing the privilege for users, and Guardium data features.

      What is most valuable?

      The solution supports a lot of databases.

      For how long have I used the solution?

      I have been using IBM Guardium Data Protection for approximately three years.

      What do I think about the stability of the solution?

      IBM Guardium Data Protection is stable.

      What do I think about the scalability of the solution?

      The solution is scalable.

      We have approximately six people using the solution.

      How are customer service and support?

      The technical support has been very good.

      How was the initial setup?

      IBM Guardium Data Protection's installation is straightforward and takes a few hours.

      What about the implementation team?

      We have five people that do the implementation and maintenance of the solution.

      What's my experience with pricing, setup cost, and licensing?

      The price of the solution could be better.

      What other advice do I have?

      I would recommend this solution to others.

      I rate IBM Guardium Data Protection a nine out of ten.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      PeerSpot user
      Information Security Analyst at a tech services company with 501-1,000 employees
      Real User
      Capture mode collects all activity and Collector stores the data for traceability
      Pros and Cons
      • "The most valuable feature is using the capture operation mode “S-TAP/K-TAP agent”, because all activities in the database are captured, including direct access to the database server by privileged users. This is useful because, even if the database server logs were deleted, the Guardium Collector has already stored such data to enable traceability of access."
      • "The possible number of databases and database servers which can be monitored by Guardium is high. For me, this is a differentiator of IBM."
      • "I have already mentioned to IBM that a primary need is to improve the number of records in the reports above 65,535."

      What is our primary use case?

      Guardium is used based on our Manual of Internal Procedures (MPI), and its uses range from creating a rule to generating customized reports. The main use case is the procedure "Investigate Incidents Recorded by Unauthorized Access," with action "notify by electronic message the manager and/or leader of the area."

      How has it helped my organization?

      Improved security through the visibility and control of all access to the databases.

      What is most valuable?

      The most valuable feature is using the capture operation mode “S-TAP/K-TAP agent”, because all activities in the database are captured, including direct access to the database server by privileged users. This is useful because, even if the database server logs were deleted, the Guardium Collector has already stored such data to enable traceability of access.

      What needs improvement?

      I have already mentioned to IBM that a primary need is to improve the number of records in the reports above 65,535.

      For how long have I used the solution?

      One to three years.

      What do I think about the stability of the solution?

      Depending on the policy and rules applied, there is a need to increase the minimum requirements (RAM and storage - HD) for better operation and not to experience hardware slowdowns due to the high flow of traffic. IBM brings the "minimums" and "recommendation." From experience in versions 9x and 10x, when installing Guardium, it's important to verify the "recommendation" requirements of IBM for stability. It is worth mentioning that the requirements (minimums or recommendation) are different for Collector and aggregator.

      What do I think about the scalability of the solution?

      The two major Database Audit and Protection (DAP) solutions are IBM Guardium and Imperva SecureSphere. There are two modes of operation of these solutions: remote agent and sniffer (out-of-band). I recommended using the remote agent to obtain direct access captures on servers. 

      Note that in non-mainframe environments, both solutions are scalable. For the mainframe environment, Guardium has updated installation agents with the latest kernels and releases. This makes a big difference in companies with mainframes, so it is necessary to keep the technology pack updated.

      Regardless of the mode of operation, when increasing the number of servers monitored it is important to re-evaluate or perform new sizing. The possible number of databases and database servers which can be monitored by Guardium is high. For me, this is a differentiator of IBM.

      How are customer service and technical support?

      On a "bad, good, and excellent" scale, I rate it as good.

      Which solution did I use previously and why did I switch?

      Initially, there were two solutions to be evaluated: Oracle and Imperva. Oracle DAP was not evaluated because it does not monitor Linux or Windows Server-only environments. 

      I evaluated Imperva and got good results. However, there is a delay by Imperva in creating updated agents for Linux and Unix, including for mainframe. For me, this is a problem because it is necessary to always keep the environment up to date. If you update the kernel or release of mainframes and do not have the agent upgraded, the DAP will not monitor.

      How was the initial setup?

      For those who do not have experience, it is complex. There are several configurations to be made, from the configuration of NTP, IP, Mask, registration of the Collectors in the Central Manager, integration with other tools like storage (backup), LDAP, SIEM, through to the application of the policies and customized rules. Note: There are some pre-set rules that can also be customized.

      What's my experience with pricing, setup cost, and licensing?

      The price of Guardium is higher than the main competitor, Imperva. In addition, it's complex as the calculation of the licensing is done by Processor Value Unit (PVU).

      However, before purchasing a DAP solution, it is important to analyze specific points to evaluate the cost-benefit of each tool. For example: Does the environment to be monitored have mainframes? If so, it's a point for Guardium. If not, a point for Imperva. Note: IBM is looking into a new licensing policy and reducing the price of Guardium.

      What other advice do I have?

      1. Read important articles related to DAP such as the "2017 Planning Guide for Security and Risk Management."
      2. Gather information from the servers (operating system with version and database types with the versions) of the environment to be monitored.
      3. Check which DAP solutions can monitor the environment.
      4. List the “mandatory requirements” and “non-mandatory requirements.” It is important to have in mind which points will be evaluated.
      5. Request PoCs with the main DAP manufacturers (IBM, Imperva, and Oracle).
      6. Do the sizing with the topology to get an idea of the requirements and cost of the project.
      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      it_user841920 - PeerSpot reviewer
      Business Development Manager at a tech services company with 10,001+ employees
      Reseller
      It made the setup easy for us
      Pros and Cons
      • "Encryption is not straightforward, but Guardium made the setup easy for us."
      • "It needs an integration with Optum."

      What is our primary use case?

      Database encryption.

      What is most valuable?

      • Encryption
      • Data activity monitoring
      • It has a set of modules.
      • I compliment with Optum for a data masking solution.

      What needs improvement?

      An integration with Optum. Optum is another solution, but it is a segmenting software, portfolio not security. However, I am selling them together as one solution, Guardium and Optum.

      For how long have I used the solution?

      Less than one year.

      How are customer service and technical support?

      I am dependent on my team for support of this product.

      Which solution did I use previously and why did I switch?

      My main solution was Micro Focus voltage data encryption solution, but it was too complicated. 

      How was the initial setup?

      Encryption is not straightforward, but Guardium made the setup easy for us.

      What other advice do I have?

      Most important criteria when choosing to partner with a company: I started working with IBM only one year back. When I started a partnership with them, IBM had the security portfolio which covered most of the region where my customers were. IBM has a name with the support along the quality of its products.

      Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
      PeerSpot user
      it_user841929 - PeerSpot reviewer
      IT Manager at a financial services firm with 1,001-5,000 employees
      Real User
      Very good for security and compliance, simple to use and manage

      What is our primary use case?

      The primary use case is security of our data in the bank.

      Performance is very good.

      How has it helped my organization?

      Security. This is the main capability that you have in this solution.

      In terms of compliance, we need to track users, database logins, and run inquiries. Guardium stores this log information very well. We don't use it for compliance with industry regulations like SOX, PCI or GDPR.

      We have integrated Guardium with our database, SQL server, Hadoop, and Oracle Database. The integration is very simple. We just installed the solution and the rest was very simple.

      I believe Guardium save us time and money. Upper management is aware of these savings.

      What is most valuable?

      It's simple to use and managing the solution. It's very, very good for security and tracking users and databases in the organization.

      What do I think about the stability of the solution?

      Stability is very good. I don’t have downtime with this solution.

      How is customer service and technical support?

      We used support to configure Guardium with Hadoop only. The support was good. I did not need to escalate this ticket.

      What's my experience with pricing, setup cost, and licensing?

      The pricing was for a big package, including all IBM products. As such, it was good value.

      Which other solutions did I evaluate?

      I don’t know because I am new in this company. I don’t know the history.

      What other advice do I have?

      When selecting a vendor, I look at the price and the scope of solution.

      My advice is to use this solution. For security and compliance it is very, very good.

      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      it_user618123 - PeerSpot reviewer
      Senior IT Consultant, Pre-Sales Manager, Project Leader at a tech services company with 51-200 employees
      Consultant
      Fulfills the international standard security requirements, such as PCI DSS.

      What is most valuable?

      • Database Activity Monitoring: Fulfills the international standard security requirements, such as PCI DSS
      • It is very transparent on all of the query access controls of the monitored databases

      How has it helped my organization?

      According to my client, it fulfills the PCI DSS standard requirements that are implemented in his bank.

      What needs improvement?

      The graphics are so lame. I am sure that the latest version of Guardium, Version 10, would have improved it perfectly.

      I see that they have improved the chart and diagram in the latest version of Guardium. However, there are some limitations on how the chart displays the data for analytic needs.

      I am not sure if Guardium has the dashboard design to see the information much better.

      For how long have I used the solution?

      I have used it for three years.

      What do I think about the stability of the solution?

      We did encounter stability issues. Do not upgrade directly to the latest fix pack unless people have confirmed that it is stable.

      What do I think about the scalability of the solution?

      There were no scalability issues.

      How is customer service and technical support?

      Technical support is always available for you. I suggest the following:

      • Call IBM and make a Severity 2 request instead of Severity 3 request.
      • Ask them to provide remote access to your system right away.
      • Prepare the log files that they usually request.

      What's my experience with pricing, setup cost, and licensing?

      They have changed the way of licensing. It is no longer according to your core. It is now based on how many servers you use. The price should be way less expensive.

      Disclosure: My company has a business relationship with this vendor other than being a customer: Optus Solution is an IBM Business partner and I work for Optus. If you are looking for a company or a consultant, you may contact me via my email: lin.guangming2010@gmail.com.
      PeerSpot user
      Buyer's Guide
      Download our free IBM Security Guardium Data Protection Report and get advice and tips from experienced pros sharing their opinions.
      Updated: March 2024
      Product Categories
      Database Security
      Buyer's Guide
      Download our free IBM Security Guardium Data Protection Report and get advice and tips from experienced pros sharing their opinions.