openskills.info
Course Preview

Database Security

Database security protects stored data from unauthorized access, modification, and exfiltration. It covers authentication, authorization, encryption at rest and in transit, auditing, injection prevention, and the principle of least privilege applied to database accounts and roles.

itDatabases and data storage

Don't Panic - Database Security

Database security keeps data confidential, correct, and available to authorized work, and it keeps security-relevant actions traceable when you must investigate a mistake or an attack. The database engine is only one part of that job. Data also moves through applications, drivers, networks, replicas, storage, logs, backups, analytics exports, and administrator tools. A weakness at any boundary can undermine stronger controls elsewhere.

Start with the data and the paths, not with a product checkbox. Classify the harm from unauthorized disclosure, modification, deletion, or loss of access. Include temporary files, snapshots, and backup media. Then map every path: application connections, admin and support access, replication and backup channels, monitoring and export jobs, management interfaces, and key- management systems. Each path is a trust boundary with an identity check, an authorization outcome, and some amount of evidence left behind.

Controls have different jobs. Network filters limit who can reach an endpoint. Authentication establishes identity. Authorization limits what that identity may do. Safe query construction keeps untrusted input out of the command structure of a query. Encryption protects selected data in transit or at rest. Audit logging records events for detection and investigation. Backup protection preserves recovery without creating an easier route to the data. No single layer proves the others.

Treat replicas, exports, and backups as first-class exposure. A hardened primary with an open secondary path is still a compromise waiting to happen. Prefer least privilege with a documented break-glass path so operations can recover without permanently wide roles.

Read the Intro for the boundary model and control layers. Use the Cheatsheet when you need the checklist for paths and controls. Landscape places database controls among related data-protection practices; Updates tracks NIST SP 800-53, which this course uses when translating techniques into reviewable organizational requirements.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources