‎IT Security Analyst at a tech services company with 11-50 employees
Real User
Audit Process Builder enhances audit tasks and compliance workflows
Pros and Cons
  • "Audit Process Builder – Workflow generator to enhance audit tasks and compliance workflows."
  • "Compliance Quick Start – Quick, GUI, step-by-step guide to automate compliance and give the customer a quick ROI."
  • "Needs easier integration with custom applications."

What is our primary use case?

As a registered IBM Business Partner, our main interaction is to deploy Guardium at client sites.

What is most valuable?

  • Audit Process Builder – Workflow generator to enhance audit tasks and compliance workflows.
  • Compliance Quick Start – Quick, GUI, step-by-step guide to automate compliance and give the customer a quick ROI.

What needs improvement?

Needs easier integration with custom applications.

For how long have I used the solution?

Three to five years.
Buyer's Guide
IBM Security Guardium Data Protection
March 2024
Learn what your peers think about IBM Security Guardium Data Protection. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
769,630 professionals have used our research since 2012.

What other advice do I have?

I would give the product a score of eight out of 10. This is due to its deep level of granularity and guided process/audit workflow generation.

Disclosure: My company has a business relationship with this vendor other than being a customer: IBM Business Partner.
PeerSpot user
it_user844485 - PeerSpot reviewer
President at a tech vendor with 1-10 employees
Real User
Helps us support security initiatives and compliance policies like HIPAA and PCI
Pros and Cons
  • "It provides a comprehensive security for databases, both on-prem and on the cloud. Among the advanced features we use automatic backups, DR."
  • "More predictive, using Watson AI would be good."

What is our primary use case?

To provide cyber security for databases.

It has performed very well.

How has it helped my organization?

It has made us more responsive and more productive, more efficient.

We use Guardium to support security initiatives and compliance policies. We are in the healthcare world, so it helps us with HIPAA compliance. It has also helped us with PCI. We haven't gone with GDPR.

We have not yet integrated Guardium with other systems we use.

It has saved us time and money by definitely making us more productive. Senior management is aware of this.

What is most valuable?

It provides a comprehensive security for databases, both on-prem and on the cloud.

Among the advanced features we use automatic backups, DR. We'd like to implement more predictive, using Watson.

What needs improvement?

More predictive, using Watson AI would be good.

What do I think about the stability of the solution?

It's very stable.

What do I think about the scalability of the solution?

It's scalable.

How are customer service and technical support?

We sometimes use technical support from IBM. It has been good, very good.

Which solution did I use previously and why did I switch?

We were using traditional cyber security stuff. But this is a pretty good product. We became an IBM business partner, we are a cyber security business partner for IBM. We have other products besides Guardium that we are marketing.

The most important criteria when selecting a vendor are their

  • stability
  • quality
  • support.

How was the initial setup?

It was straightforward.

What other advice do I have?

Buy it.

Disclosure: My company has a business relationship with this vendor other than being a customer: IBM Business Partner.
PeerSpot user
Buyer's Guide
IBM Security Guardium Data Protection
March 2024
Learn what your peers think about IBM Security Guardium Data Protection. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
769,630 professionals have used our research since 2012.
PeerSpot user
Pre Sales Engineer at a tech services company with 501-1,000 employees
Reseller
It provides visibility for the DB activity and secures the customer information in the DB from any misuse.

What is most valuable?

All the features are useful for the customer and they have many use cases, especially for DB protection.

They have a module called Redaction. For query rewriting, it can protect some data stored in the table by the DB admin to return the masked data, in case he tries to view our customer personal information such as phone numbers,names, account number etc.

In some cases it blocked the bad user from deleting or copying data , For example, in use cases to block creation of the users on the DB without filing forum/ following the company policy.

How has it helped my organization?

It provides the customer to help secure the DB, especially for the multi-DB environments. It also provides visibility for the DB activity, secures the customer information in the DB, from any privilege misuse by an insider.

What needs improvement?

The FAM module needs to be improved. This module is for file activity monitoring and here if IBM would focus on marketing this part, it will be good as the end-user can monitor any configuration file in servers and not only the DB.

For how long have I used the solution?

I have used this solution for around six years.

What do I think about the stability of the solution?

Some issues have been experienced but no big issues as such. The solution is 90% stable.

What do I think about the scalability of the solution?

We have not encountered any scalability issues.

How is customer service and technical support?

I would give the technical support a 9/10.

How was the initial setup?

The setup was very easy. It took us around one day to set it up and running.

What's my experience with pricing, setup cost, and licensing?

You should make sure of the DB size before you buy the product. It is also important to define the requirement very carefully as it could affect the sizing. You should make sure of the monitoring mode that they would like to apply.

Which other solutions did I evaluate?

We looked at the Oracle and Imperva solutions.

What other advice do I have?

Take care of the scope and the monitoring mode. Also, if the size of the DB is high then do not do it over virtual.

Disclosure: My company has a business relationship with this vendor other than being a customer: We're resellers.
PeerSpot user
Information Security Consultant at a tech services company with 51-200 employees
Reseller
Good reporting and supports data-level access control
Pros and Cons
  • "The most valuable features are the reporting and data-level access control."
  • "The price of this solution is quite high for smaller organizations, so they should release a version that is affordable for small and medium-sized businesses."

What is our primary use case?

We are a solution provider and IBM Guardium is one of the database products that we implement for our clients. Our customers for Guardium are mostly banks and they use it for PCI compliance.

What is most valuable?

The most valuable features are the reporting and data-level access control.

The interface is easy to use and the learning curve is not very steep.

What needs improvement?

The price of this solution is quite high for smaller organizations, so they should release a version that is affordable for small and medium-sized businesses.

For how long have I used the solution?

I have been working with IBM Guardium for about a year and a half.

What do I think about the stability of the solution?

The stability depends, in part, on how much the client can give the appliance in terms of resources. Overall, I think that it's a really stable appliance, as long as you keep it up to date with all of the patches and updates.

What do I think about the scalability of the solution?

I have done at least one really large-scale deployments and my impression is that it scales really well. 

How are customer service and technical support?

I have not personally interacted with IBM's technical support. Normally, my seniors in the company would do that.

How was the initial setup?

The initial setup is straightforward. It took about a month for me to get started on it. I used the resources from the security learning academy to begin.

The length of time required for deployment depends on the scale and the internal processes. The largest that I have done took more than a year to complete, although these clients have lots of stuff happening in their environment that had to be taken care of. At times, things like this put us off of our schedule.

What about the implementation team?

We implement and deploy this solution for our clients. People from the client's side are also required. We have the Guardium Administrator, who is usually the project lead. The client will have database administrators, network administrators, IT staff to set up the appliance, and somebody from information security.

What other advice do I have?

My advice to anybody who is implementing this solution is to start small, with a test environment, and then scale it up. This way, if there is a fault at the beginning then it won't be multiplied by the time you have a larger deployment and are fully integrated. In this way, you will see if it meets the requirements.

Overall, this is a wonderful product.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
it_user593442 - PeerSpot reviewer
Technical Specialist/Consultant Ibm at a tech services company with 5,001-10,000 employees
Consultant
Monitors database activity, and blocks firewalls and malicious connections.

What is most valuable?

The main features are database activity monitoring and firewall feature blocking.

How has it helped my organization?

I'm working as a consultant for security products. I'm not a user of this product. Guardium is helping customers to get insights into who is accessing company data, when they are doing it, and from which location.

Guardium can block malicious connections to the databases. For example, if someone is accessing sensitive data in a production database during non-working hours, Guardium can block this connection.

What needs improvement?

I would like to see a better GUI. IBM is working on GUI improvements with every new release.

For how long have I used the solution?

I have used this solution for five years.

What do I think about the stability of the solution?

I did not encounter any issues with stability.

What do I think about the scalability of the solution?

The system is scalable.

How is customer service and technical support?

Technical support is fast and responsive. The typical response time is less than two hours.

How was the initial setup?

The initial setup is relatively simple. It depends on how many collectors and aggregators are in the setup and the number of databases included in the monitoring solution.

After the initial setup, the level of complexity depends on the customer’s needs.

What other advice do I have?

Ask for a PoC project and then decide.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security Engineer at a tech services company with 501-1,000 employees
Real User
No crashes and great accountability
Pros and Cons
  • "The most valuable features of this product are activity monitoring on the database servers, discovery capabilities, and vulnerability scanning."
  • "An area for improvement would be the user interface - currently, it takes around two to three months to become comfortable using it."

What is our primary use case?

My primary use of this solution is for database activity monitoring.

What is most valuable?

The most valuable features of this product are activity monitoring on the database servers, discovery capabilities, and vulnerability scanning.

What needs improvement?

An area for improvement would be the user interface - currently, it takes around two to three months to become comfortable using it. In the next release, I would like to see more integration with other vault vendors.

For how long have I used the solution?

I've been using this solution for five years.

What do I think about the stability of the solution?

The product is stable - during my time using it, I have not had any crash problems with the servers, and I haven't needed to do any restarts.

How are customer service and support?

I haven't had any problems with the global and local support for this product.

How was the initial setup?

The initial setup was basic and easy and didn't take much time.

What's my experience with pricing, setup cost, and licensing?

The cost of this product is reasonable but could be lowered to a more competitive level.

What other advice do I have?

Guardiam's accountability is good - by design, it doesn't give any root privilege to customers, which means we don't have highly important privilege for access to Guardiam. They use only a user level, so kernel-level users are prohibited, which means there aren't any accidental effects from the customer side. I would rate this solution as eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free IBM Security Guardium Data Protection Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2024
Product Categories
Database Security
Buyer's Guide
Download our free IBM Security Guardium Data Protection Report and get advice and tips from experienced pros sharing their opinions.