Proactive vulnerability assessments

Guardium® Data Protection provides automated vulnerability scanning for databases, helping ensure that security teams can proactively detect and remediate Db2 security weaknesses. It helps identify unpatched vulnerabilities, weak authentication settings, and misconfigured security policies.

About this task

Many DB2 environments run with unpatched software, weak access configurations, or inconsistent encryption — often due to the sheer complexity of identifying and resolving issues across instances. DBAs frequently lack a centralized view of known vulnerabilities (CVEs), risky privileges, or misconfigurations, putting sensitive workloads at unnecessary risk.

Guardium Data Protection’s built-in Vulnerability Assessment engine enables DB2 administrators to scan, evaluate, and remediate security issues quickly and consistently. The Vulnerability Assessment engine uses industry benchmarks (e.g., CVEs, STIG, CIS) to assess control gaps in authentication, auditing, encryption, user permissions, and configuration hardening. Unlike static checklists, the Vulnerability Assessment engine dynamically adapts to evolving threats and can be scheduled for recurring scans.

Guardium Data Protection helps organizations automate vulnerability assessments by:

  • Scanning databases and data sources for potential vulnerabilities
  • Identifying and classifying vulnerabilities based on severity and risk
  • Providing recommendations for remediation and mitigation
  • Tracking and monitoring vulnerability status over time
  • Generating reports and alerts to notify administrators of new or unresolved vulnerabilities
  • Integrating with existing security tools and workflows to streamline vulnerability management

Procedure

  1. On the Guardium Data Protection homepage, expand the navigation menu by clicking the navigator icon on the left side of the screen, as in the following example.

    Welcome homepage for GDP

  2. From the expanded navigation menu, go to My Dashboards > My Custom Dashboards > 03A Vulnerability assessment report.
    screenshot showing menu expansion

  3. To read descriptions of each chart you can view on the vulnerability assessment dashboards, see the following topics:

What to do next

Want to create your own dashboard with Db2 sample data? For instructions, see Connecting Guardium to Db2 sample data.