How to transfer sensitive data to InfoSphere Discovery
Take sensitive data information, identified and classified in IBM Security Guardium and transfer that information to InfoSphere® Discovery.
Both IBM Guardium and InfoSphere Discovery have the capability to identify and classify sensitive data, such as Social Security Numbers or credit card numbers.
A customer of the IBM Guardium product can use a bidirectional interface to transfer identified sensitive data information from one product to another.
Note: In IBM Guardium ,
the Classification process is an ongoing process that runs periodically.
In InfoSphere Discovery,
Classification is part of the Discovery process that usually runs
once.
Note: The data will be transferred via CSV files.
The summary of Export/Import procedures is as follows:
- Export from Guardium - Run the predefined report (Export Sensitive Data to Discovery) and export as CSV file.
- Import to Guardium - Load to a custom table against CSV datasource; define default report against this datasource.
Follow these steps:
- Export from Guardium - Export Classification Data from IBM Guardium to InfoSphere Discovery
- As an admin user in the Guardium® application,
go to Tools > Report Building >Classifier Results Tracking >
Select a Report > Export Sensitive Data to Discovery (See screenshot). Note: Add this report to the UI pane (it is not by default).
- Click on Customize icon on Report Result screen and specify the search criteria to filter the classification results data to transfer to Discovery.
- Run the report and click on Download All Records icon.
- Save as CSV and import this file to Discovery according to the InfoSphere Discovery instructions.
- Import to Guardium - Import Classification Data from InfoSphere Discovery to IBM Guardium
- Export the classification data as CSV from InfoSphere Discovery based on InfoSphere Discovery instructions.
- As an admin user in the Guardium application,
go to Tools > Report Building >Custom Tables screen, select
ClassificationDataImport and click on Upload Data button.
(See screenshot).
- In Upload Data screen, click on Add Datasource, click on New button,
define the CSV file imported from Discovery as new datasource
(Database Type = Text). See the following screenshot of CSV
Datasource definition.Note: Alternatively you can load the data directly from Discovery database if you know how to access the Discovery database and Classification results data.
- After defining the CSV as Datasource, click on Add button in Datasource list screen.
- In Upload data screen click on Verify Datasource and then Apply.
- Click on Run Once Now button to load the data from the CSV.
- Go to Report Builder, select Classification Data Import report, Click on Add to Pane to add it to your Portal and then navigate to the report.
- Access the Report, click on Customize to set the From/To dates and execute the report.
The report result has the classification data imported from InfoSphere Discovery. Double click to invoke APIs assigned to this report. The data imported from Discovery can be used for the following:
- Add new Datasource based on the result set.
- Add/Update Sensitive Data Group.
- Add policy rules based on datasource and sensitive data details.
- Add Privacy Set.
Interface Signature | Example |
---|---|
Type | DB2® |
Host | 9.148.99.99 |
Port | 50001 |
dbName (Schema name for DB2 or Oracle, db name for others) | cis_schema |
Datasource URL | |
TableName | MK_SCHED |
ColumnName | ID_PIN |
ClassificationName | SSN |
RuleDescription | Out-of-box algorithm of InfoSphere Discovery |
HitRate | 70% - not available for export in Guardium Vers. 8.2 |
ThresholdUsed | 60% - not available for export in Guardium Vers. 8.2 |