Database Security
Database security protects stored data from unauthorized access, modification, and exfiltration. It covers authentication, authorization, encryption at rest and in transit, auditing, injection prevention, and the principle of least privilege applied to database accounts and roles.
itDatabases and data storage | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic - Database Security
Database security keeps data confidential, correct, and available to authorized work, and it keeps security-relevant actions traceable when you must investigate a mistake or an attack. The database engine is only one part of that job. Data also moves through applications, drivers, networks, replicas, storage, logs, backups, analytics exports, and administrator tools. A weakness at any boundary can undermine stronger controls elsewhere.
Start with the data and the paths, not with a product checkbox. Classify the harm from unauthorized disclosure, modification, deletion, or loss of access. Include temporary files, snapshots, and backup media. Then map every path: application connections, admin and support access, replication and backup channels, monitoring and export jobs, management interfaces, and key- management systems. Each path is a trust boundary with an identity check, an authorization outcome, and some amount of evidence left behind.
Controls have different jobs. Network filters limit who can reach an endpoint. Authentication establishes identity. Authorization limits what that identity may do. Safe query construction keeps untrusted input out of the command structure of a query. Encryption protects selected data in transit or at rest. Audit logging records events for detection and investigation. Backup protection preserves recovery without creating an easier route to the data. No single layer proves the others.
Treat replicas, exports, and backups as first-class exposure. A hardened primary with an open secondary path is still a compromise waiting to happen. Prefer least privilege with a documented break-glass path so operations can recover without permanently wide roles.
Read the Intro for the boundary model and control layers. Use the Cheatsheet when you need the checklist for paths and controls. Landscape places database controls among related data-protection practices; Updates tracks NIST SP 800-53, which this course uses when translating techniques into reviewable organizational requirements.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://cheatsheetseries.owasp.org/cheatsheets/Database_Security_Cheat_Sheet.html
Supports
- Database network isolation and restricted management access
- Encrypted database connections and server-certificate verification
- Secure authentication, credential storage, granular permissions, and hardening
- Low-privilege service accounts, security updates, protected backups, and relational database scope
- https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
Supports
- SQL injection as unsafe mixing of untrusted input and query structure
- Prepared statements with bound parameters as the primary defense
- Allow-list mapping for identifiers and sort direction when binding is unavailable
- Dynamic SQL risk in stored procedures and least privilege as damage reduction
- https://cheatsheetseries.owasp.org/cheatsheets/NoSQL_Security_Cheat_Sheet.html
Supports
- NoSQL injection through unsafe query objects or query strings
- Risks from exposed management interfaces, weak access control, secrets, logs, and backups
- Server-side construction of safe driver query objects and validation of permitted fields and operators
- https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-53r5.pdf
Supports
- Least privilege, separation of duties, privilege review, and logging of privileged functions
- Audit-record fields, storage capacity, failure response, search, time stamps, protection, and separate repositories
- Cryptographic protection for transmission confidentiality and integrity
- Protection of information at rest, including selected cryptographic mechanisms and secure offline storage
- Controlled key management, system backup, recovery, and configuration controls
- https://www.postgresql.org/docs/current/client-authentication.html
Supports
- Authentication as establishment of client identity
- Restriction of which database users can connect
- Relationship between client authentication and role-based privileges
- https://www.postgresql.org/docs/current/user-manag.html
Supports
- PostgreSQL roles as users or groups
- Role ownership, privileges, and membership
- Role management as PostgreSQL authorization mechanics
- https://www.postgresql.org/docs/current/ddl-rowsecurity.html
Supports
- Per-user row restrictions for read and modification operations
- Policy scope, role interaction, owner and bypass behavior, and execution context
- Need to test both permitted and denied behavior
