
<p>It's hardly a new idea for network administrators to use segmentation and the development of DMZs to better partition and protect sensitive systems away from rest of the IT infrastructure asset herd. But to DBAs and web application developers, these ideas may be a little more foreign. According to many data security experts, though, application and data owners would do well to learn a few lessons from their networking brethren.</p><p>[How are your web apps bringing databases under fire? See ">10 Ways Developers Put Databases At Risk. ]</p><p>With better logical separations within database and application environments, organizations could stand to mitigate risks when hackers compromise parts of the data-bearing infrastructure, they say.</p><p>"(It's) the same design model as submarines and ships that keeps them afloat when their hull is breached by segmenting the systems," says Mark Goudie, managing principal of the RISK Team for Verizon Enterprise Solutions. "This theory does not just apply to physical segmentation of networks and systems, but should be applied to database security models as well."</p><p><a href="http://www.darkreading.com/database-security/167901020/security/news/240007661/dbas-and-developers-need-to-better-segment-data-access.html">Keep reading...</a></p>