Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Warning

IDERA, Inc. customers are solely responsible for ensuring compliance with the laws and standards affecting their business. IDERA, Inc. does not represent that its products or services ensure that customer is in compliance with any law. It is the responsibility of the customer to obtain legal, accounting, or audit counsel as to the necessary business practices and actions to comply with such laws.

6.

...

3 New Features

...

Security Enhancements

Anchor
SQLCM-

...

6760
SQLCM-

...

SQL Compliance Manager 6.2 improved to determine if an Alert Rule has been configured as 'Email Notification' or 'Email Summary Notification', users no longer are required to edit the alert rule. The rule description has been enhanced to make it convenient to distinguish between the two without the need for alert rule modifications.

...

6760
Essential Security Permissions for SQLCM to Function

SQL Compliance Manager 6.2 upgraded to provide a CLI command line for registering a server, grooming, archiving, and verifying audit data integrity - version 6.2 is now augmented with CLI for enabling and disabling auditing servers.

...

SQL Compliance Manager 6.2 improved and added the number of rows at the end of the reports to ease access to the information contained in each report.

Security Enhancements

...

SQL Compliance Manager 6.2 enhanced security by deploying a strong Advanced Encryption Standard (AES) algorithm to meet the latest high standards of our large enterprise customers. The Advanced Encryption Standard (AES) is an algorithm that uses the same key to encrypt and decrypt protected data. Instead of a single round of encryption, data is put through several rounds of substitution, transposition, and mixing to make it harder to compromise.3 release delivers security permissions based on the least privilege principle (as opposed to permissions based on standard user roles such as sysadmin) to further enhance the data security per user within the product.

6.2 Fixed Issues 

  • Anchor
    SQLCM-67486883
    SQLCM-6748
    DDL, DML, and DROP events are correctly shown in the "Audit Events" tab after performing the DDL action on the "Sensitive Column" when using the "via Audit Logs" collection method.
    6883
    Fixed an issue where DDL AnchorSQLCM-6728SQLCM-6728Audit events for "insert" are accurately being recorded for Sensitive columns with "select and DML activity" enabled.
    AnchorSQLCM-6729SQLCM-6729Resolved the issue where Trace events were not being correctly captured for "delete from <table>" audit events when sensitive columns with "select and DML activity" were configuredcaptured for server-level privilege users configured through a domain group.
  • Anchor
    SQLCM-64036364
    SQLCM-64036364
    Fixed an Resolved the issue where the number of Logout events captured was significantly more than the number of Login events.
    AnchorSQLCM-6539SQLCM-6539Resolved the issue where a warning message was displayed in the Event Viewer after execution of the trace file out to the collection Server for processing. Regulatory Compliance Check report was showing "No" at server-level for PCI DSS guideline. 
  • Anchor
    SQLCM-67736860
    SQLCM-67736860
    Fixed an issue where the "Delete" DML events were shown twice after executing a single "Delete" query on the "Sensitive Columns" table when "Trace" or "Audit Logs" collection methods were used IP Address Auditing checkbox was unchecked after importing an exported audit setting file.
  • Anchor
    SQLCM-67696855
    SQLCM-67696855
    Resolved the issue where the events table integrity check did not detect changes done on hash columns.
    AnchorSQLCM-6750SQLCM-6750The “SQL Statement” content is correctly displayed in the “Event Properties” after executing the DDL query if the “via SQL server Audit specification” is usedAddressed an issue with Audit Events not appearing on SQLCM console when CM repo was hosted on a Case Sensitive SQL instance.
  • Anchor
    SQLCM-67496816
    SQLCM-67496816
    Resolved Solved the issue where the "+" icon was missing for the DDL column-sensitive event in the "Audit Events" tab.
    AnchorSQLCM-6721SQLCM-6721Addressed an issue where the layout was broken for reports downloaded in PDF and TIF formats.
    AnchorSQLCM-6697SQLCM-6697Resolved an issue where Events were not captured as expected with Extended Events and SELECT auditing was enabled.
    AnchorSQLCM-6671SQLCM-6671Fixed the issue where the Bin file was not getting updated for the Privileged User set up through a domain group at the server level. AnchorSQLCM-6629SQLCM-6629 Resolved an issue where "Unknown Publisher" was displayed in the "User Account Control" when installing SQLCM.
    AnchorSQLCM-6664SQLCM-6664 Addressed an issue where an error message would come up when trying to import audit settings. of multiple alerts being logged for a single event.
    • The number of Data and Event alerts is consistent with the number of audit events generated.
    • The email alerts have been improved with the appropriate event description.


For more information about new features and fixed issues in version 6.13, see Previous new features and fixed issues.

...