Home > SQL Server Security School: Class syllabus
School:
EMAIL THIS

SQL Server Security School: Class syllabus

28 Apr 2005 | SearchSQLServer.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Chip Andrews, Director of Research and Development for Special Ops Security, Inc. is your SQL Server Security professor. Chip is the founder of the SQLSecurity.com website which focuses on Microsoft SQL Server security topics and issues. He has over 14 years of secure software development experience helping customers design, develop, deploy and maintain reliable and secure software. Chip has been a primary and contributing author to several books including Special Ops: Network and Host Security for Microsoft, Oracle and UNIX, SQL Server Security, and Hacking Exposed: Windows 2000. He also served as a technical reviewer for the book SQL Server Security Distilled. He is a prominent speaker at security conferences, where he provides expertise on Microsoft SQL Server security issues and secure application design. SQL Server Security School is in session -- enjoy!


SQL Server Security School

Lesson 1: Minimizing SQL Server service, login and user accounts
By default, SQL Server service accounts, logins, and user accounts have a large number of rights and permissions needed to support the myriad options and tools provided with SQL Server. A better strategy would be to lock down the permissions as much as possible and then only "give back" the rights needed to complete the task at hand. Firewall administrators have lived by this axiom for years, why not database administrators?
Listen to Lesson one right now.
Sponsored by: Imceda Software

Lesson 2: SQL Server discovery challenges and solutions
SQL Servers can be hard to locate on today's networks. Personal firewalls, non-default SQL Server TCP ports, and users who only enable the server when they need it can all be lurking on your network without your knowledge. Making sure that you can find all of the SQL Servers on your network is critical to securing them. In this lesson, we'll discuss all of the tools and techniques at your disposal to get this done.

Listen to Lesson two right now.
Sponsored by: Imceda Software

Lesson 3: Securing SQL Servers using Group Policy
Between development workstations, a myriad of third-party products and line-of-business systems that use SQL Server, the average organization may have hundreds if not thousands of SQL Server systems to configure and secure. Doing this by hand is labor-intensive and likely infeasible for most. By implementing company policies and enforcing them through Active Directory and Group Policy, you can literally affect thousands of installations at once and enforce order from chaos.

Listen to Lesson three right now.
Sponsored by: SQL Server Adviser newsletter

Lesson 4: Defensive programming against SQL Injection
SQL injection is still among the most ubiquitous of application security vulnerabilities despite plenty of press on the problem. In order to mitigate this, we need more policy compliance and process in the application development space, not just penetration testing and education. In this webcast we'll discuss what you should be doing early on in your development projects to address this problem and how many of these techniques can be applied to existing products.

Listen to Lesson four right now.
Sponsored by: SQL Server Adviser newsletter


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
SQL Server Security
Meet compliance requirements with improved database security practices
Hardening the network and OS for SQL Server security
Securing the server and database in SQL Server
SQL Server security made simple and sensible
Blog: Protect your databases from the internal threat
Setting up SQL Server Service Broker for secure communication
The keys to database backup protection for SQL Server
Understanding transparent data encryption in SQL Server 2008
The fine line between not encrypting your databases and breach notification
Securing SQL Server with access control, login monitoring and DDL triggers

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
data corruption  (SearchSQLServer.com)
data hiding  (SearchSQLServer.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Secure SQL - Data Security for Your Database
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2005 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts