Back to Insights Compliance

Hardening Database Access: The New Standards Every Organization Must Know

Data Access Security: Transitioning from General Definitions to Clear Requirements

What are the “acceptable measures” for securing access to databases? Information security is at the heart of privacy protection. It is for good reason that the legislator established dedicated regulations for data security. At the center of the Data Security Regulations stands the protection of the database and its systems, primarily focusing on access control. Recently, the Privacy Protection Authority published a draft for public comment clarifying what constitutes “acceptable measures” and the standards required of you to comply with the provisions of Regulation 9(a) of the Privacy Protection Regulations. These provisions specifically address securing access to databases.

What is Regulation 9(a) and why is it so important?
In short, the regulation mandates that the data controller (owner) and the data processor (holder) take “acceptable measures” to ensure that access to the database and its systems is performed exclusively by authorized personnel. Failure to comply with these requirements may lead to data compromise and the imposition of significant financial sanctions. The new document aims to eliminate ambiguity and define those measures, based on international standards (such as NIST) and market best practices.

Three Authentication Groups: How do we identify a user?
It is customary to divide identity authentication methods into three main categories:
1. Something you know: Information known only to the user, such as a password or PIN (Note: An ID number is not a sufficient authentication factor!).
2. Something you have: A physical or digital component, such as a One-Time Password (OTP) sent to a mobile device, an authenticator app, or a smart card.
3. Something you are: Physiological or behavioral characteristics (biometrics), such as a fingerprint, voice recognition, or facial recognition.

Three Levels of Authentication
The Privacy Protection Authority defines three authentication levels based on the database type:
– Level 1 (Basic): Requires single-factor authentication (e.g., a password).
– Level 2 (High): Mandates Multi-Factor Authentication (MFA) that is phishing-resistant.
– Level 3 (Very High): Mandates MFA based on cryptographic protocols and non-exportable public keys.

What is the expected change? In other words, what is required of your organization?
The expectation is a hardening of “acceptable measures.” Aligning the authentication level within the organization is derived from the security level of the database. For example, using Multi-Factor Authentication (MFA) with at least two different factors significantly strengthens defense and reduces the risk of a breach. However, it is first necessary to examine who manages the database, who holds access permissions, and more.

A Concluding Tip
Remember that for now, this is only a draft. Technology advances rapidly, and the Authority may update the document from time to time. It is important to remember that the responsibility to evaluate concrete access measures always rests with the data controller and the processor. Therefore, prepare accordingly.

Interested in a gap analysis regarding the requirements of the Privacy Protection Law in general, and Amendment 13 in particular? Contact the experts at IPV Security! For a professional consultation, you can reach us via email at info@ipvsecurity.com or by phone at 077-4447130. IPV Security has specialized for 20 years in information security, cyber, risk assessments, and standards and regulations regarding data security and more.

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation