19 top products for data masking
Gartner defines data masking as “a technology aimed at preventing the abuse of sensitive data by providing users with fictitious yet realistic data instead of real and sensitive data while maintaining their ability to carry out business processes.” In their report “Market Guide for Data Masking,” authors Marc-Antoine Meunier and Ayal Tirosh review 19 top products for data masking.
Blue Talon - Data-Centric Security
This product offers data mapping, data activity and applied masking, Gartner says. It has general database reporting and metadata. It is focused on providing data access visibility and control. It features fine-grained user access control, filtering, and DDM capabilities for big data and RDBMSs.
CA - CA Test Data Manager for Masking and Subsetting
This product offers data mapping, data activity and applied masking, Gartner says. It has general database reporting and metadata. Its focus is on test data management. It features SDM technology aimed at complex and large environments with a multiplicity of various, interconnected databases. Its DDM approach for RDBMS requires schema changes. CA Technologies acquired Grid Tools in 2015.
Camouflage - CX-Mask and CX-Dynamic
These products offer reporting on the location of sensitive information identified by, for example, PCI DSS, HIPAA and FERPA in the U.S., PIPEDA in Canada, and the EU Data Protection Directive, as well as the masking rules applied to such data, Gartner says. Available are managed discovery and masking services. Camouflage Partners with Activio to deliver DM in test data virtualization environments. Camouflage SDM is also available through a partnership with Imperva, which provides additional data security options, including DAP.
Compuware - Data Privacy Solution
This product offers data mapping and applied masking report, Gartner says. It offers generic audit reporting for compliance. Compuware is largely focused on the mainframe platform, but also offers support for hybrid non-mainframe environments. It offers a portfolio of software development and testing tools in addition to data masking. Dynamic rules for masking help manage same data stored differently across the environment.
Dataguise - DgSecure
This product offers data mapping and applied masking report, Gartner says. It has prebuilt reports for PCI, HIPAA, and personally identifiable information (PII). It is focused on masking and encryption (including FPE) for big data, but also provides support for databases and unstructured data. Dataguise complements its DM offering with DgSecure Monitor to monitor sensitive data access and detect anomalies, and DgSecure Dashboard for data security analytics.
Delphix - Delphix Masking Engine and DMSuite DDM
These products offer data mapping and applied masking report, Gartner says. They align with predetermined rules for HIPAA, PCI DSS and the Sarbanes-Oxley Act (SOX). The Delphix Masking Engine (formerly Axis DMsuite) is now integrated with the Delphix data virtualization platform, which saves data storage and simplifies data subset management. DDM is offered via a partnership with HexaTier. Delphix acquired Axis Technology Software in 2015.
HexaTier - Dynamic Data Masking
This product’s reporting aligns with predetermined rules for HIPAA, PCI DSS and SOX, Gartner says. Previously known as GreenSQL, HexaTier addresses a broad spectrum of security needs by offering DAP and DDM (including DDM of stored procedures and DDM for separation-of-duty use cases) for on-premises and cloud databases. It integrates the policy management of DDM and DAP policies through a single console. HexaTier was acquired by Huawei at the end of 2016.
HPE Security - HPE SecureData Enterprise
This product offers data mapping and applied masking report, Gartner says. It has preset reporting for PCI DSS. An OEM instance of Splunk is also built into HP SecureData for event viewing. HPE Security offers tokenization, encryption (including FPE) and masking. It notably offers big data SDM and DDM which is integrated with HPE Vertica. Teradata also has an agreement to resell SecureData. HPE acquired Voltage Security in 2015, and those assets are in the process of being spun off and merged with Micro Focus.
IBM - InfoSphere Optim Data Privacy and IBM Security Guardium
This product offers data mapping and applied masking report with masking strength, Gartner says. It has prebuilt reports for PCI DSS and HIPAA. IBM markets its SDM product as InfoSphere Optim Data Privacy. DDM can be acquired as part of IBM Security Guardium Data Activity Monitor Advanced Edition (an appliance), or as part of InfoSphere Optim Data Privacy (a software package).
Infomatica - Persistent Data Masking, Cloud Test Data Management and Dynamic Data Masking
These products offer data mapping and applied masking report, Gartner says. They feature general reporting that can be used for PCI DSS, HIPAA and other compliance mandates. Informatica is active in other markets often requested by customers in conjunction with DM: customer MDM, data quality, data integration, enterprise integration platform as a service, and structured data archiving and application retirement. Informatica also complements DM with Secure@Source, a product that provides enterprise-wide data discovery and security analytics. DM as a service is available as part of its Cloud Test Data Management offering.
IRI – FieldShield, RowGen and Cellshield
Mentis – iDiscover, iScramble and iMask
These products offer data mapping and applied masking report with masking strength, Gartner says. Mentis DM is part of a broad suite of data security technologies that also includes data access monitoring, database intrusion prevention, tokenization, encryption and sensitive data retirement.
Microsoft - SQL Server 2016 and Azure SQL Database
These products offer general database reporting that provide data mapping and applied masking, Gartner says. The first release of DDM was introduced in Azure SQL and SQL Server 2016. Microsoft's DDM is part of the database and requires no installation or separate licensing.
Net2000 - Data Masker DataBee
This product offers data mapping and applied masking report, Gartner says. Net 2000 offers the Data Masker SDM tool, accompanied by its DataBee subsetting tool. They are focused on Oracle and SQL Server databases. Net 2000 customers span the U.S., Europe and the Asia/Pacific region.
Oracle - Data Masking and Subsetting and Data Redaction
This product offers data mapping and applied masking report, Gartner says. It aligns with predetermined rules for HIPAA, PCI DSS and PII. Oracle's SDM tool is available with Oracle Enterprise Manager, which also includes data management functionality, such as provisioning, cloning and archiving. Oracle also offers broad data security technologies, such as encryption, key management, database audit and protection, and privileged user access control. Oracle's DDM is part of the Oracle DB and requires no installation. Oracle SDM does not require a separate installation for Oracle Enterprise Manager users, and also supports non-Oracle platforms and applications.
Privacy Analytics – QuintilesIMS, Eclipse, Lexicon and Risk Monitor
These products offer data mapping and applied masking report with masking strength and statistical measurements of re-identification risk, Gartner says. They focus on compliance reporting, and have prebuilt reports for HIPAA. Privacy Analytics' technology and methods are primarily aimed at healthcare, financial and telecommunications organizations seeking quantifiable and defensible risk assessments that de-identified sensitive data can withstand attacks and the scrutiny of audits. Privacy Analytics was acquired by Quintile Sims in May 2016.
SecuPi - SecuPi Platform
This product features a masking configuration report and forensics auditing. SecuPi provides DDM at the application tier as part of an offering that also includes externalized authorization management (EAM), application data access monitoring, and user behavior analytics.
Solix Technologies - Enterprise Data Management
This product offers data mapping and applied masking report, Gartner says. It has prebuilt reports for PCI DSS and HIPAA. Solix Technologies' DM capabilities are complemented by data management, archiving and application retirement focused on popular ERP and CRM applications, and big data. Solix also offers managed service DM and data management.
TCS – MasterCraft and DataPlus
These products offer data mapping and applied masking report with masking strength, Gartner says. They offer report templates for different regulation domains. In addition to DM, TCS offers data management solutions that are often requested alongside DM, such as synthetic data generation, test data management (TDM), data profiling and governance of enterprise data. TCS also has a strong global reputation for professional services and has the capacity to provide DM services.