Announcement

Collapse
No announcement yet.

how can i secure database files?

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • how can i secure database files?

    How can i protect my database files from Theft by someone by encrypt or protect it from open from other server and location or copy to other place...

    please advice...

  • #2
    Re: how can i secure database files?

    1) Secure your physical server (locks etc)
    2) reduce the attack surface by updates, closing ports etc.
    3) restrict your accounts which have admin access to the server
    4) ditto admin accounts in SQL
    5) consider encrypting some databases: http://www.kodyaz.com/articles/sql-s...p-by-step.aspx but remember this imposes a fairly large overhead on system resources.
    Tom Jones
    MCT, MCSE (2000:Security & 2003), MCSA:Security & Messaging, MCDBA, MCDST, MCITP(EA, EMA, SA, EDA, ES, CS), MCTS, MCP, Sec+
    PhD, MSc, FIAP, MIITT
    IT Trainer / Consultant
    Ossian Ltd
    Scotland

    ** Remember to give credit where credit is due and leave reputation points where appropriate **

    Comment


    • #3
      Re: how can i secure database files?

      i am already did 1-4 but about the 5th one how can encrypt the mdf and ldf files

      Comment


      • #4
        Re: how can i secure database files?

        Did you actually look at the link I posted as part of step 5?
        It is called "Microsoft SQL Server 2005 Database Encryption Step-by-Step"
        This might give you some help
        Tom Jones
        MCT, MCSE (2000:Security & 2003), MCSA:Security & Messaging, MCDBA, MCDST, MCITP(EA, EMA, SA, EDA, ES, CS), MCTS, MCP, Sec+
        PhD, MSc, FIAP, MIITT
        IT Trainer / Consultant
        Ossian Ltd
        Scotland

        ** Remember to give credit where credit is due and leave reputation points where appropriate **

        Comment


        • #5
          Re: how can i secure database files?

          yes i read it...
          But my scenario i am running logging shipping between 2 servers and i am going to secure the destination one
          and the article modify structure... i am only need to prevent any body to take copy of databases file and access from outside server

          Comment


          • #6
            Re: how can i secure database files?

            Sorry, my crystal ball AND psychic powers must have been on the blink again I completely failed to pick up any of the log shipping stuff in your original post in the thread and thought you were asking about encryption of a database. Silly me -- I must have been fooled by "protect my database files from Theft by someone by encrypt" and "how can encrypt the mdf and ldf files"

            Please follow 1-4 in my list above and your server should be OK. Also implement a secure VPN for shipping the logs over (you should have this already) and apply all security measures to both servers. If you are worried, hire a security consultant to check your network internally and attempt penetration testing for external security.
            Last edited by Ossian; 13th February 2011, 13:06.
            Tom Jones
            MCT, MCSE (2000:Security & 2003), MCSA:Security & Messaging, MCDBA, MCDST, MCITP(EA, EMA, SA, EDA, ES, CS), MCTS, MCP, Sec+
            PhD, MSc, FIAP, MIITT
            IT Trainer / Consultant
            Ossian Ltd
            Scotland

            ** Remember to give credit where credit is due and leave reputation points where appropriate **

            Comment


            • #7
              Re: how can i secure database files?

              ok thx alot

              Comment

              Working...
              X