Skip to content

DBAzine.com

Sections
Personal tools
You are here: Home » Blogs » Craig Mullins Blog » Craig Mullins: Perspectives on Database Management » "Implementing Database Security and Auditing" - A Useful, Timely Book
Best Practices
For IT best practices, my IT shop uses:
ITIL
CobIT
Balanced Scorecard
Six Sigma
None of the above

[ Results | Polls ]
Votes : 1
 

"Implementing Database Security and Auditing" - A Useful, Timely Book "Implementing Database Security and Auditing" - A Useful, Timely Book

From time-to-time I will use my blog to promote a particularly good database-related book. And Ron Ben Natan's new book on database security and auditing merits your attention.
In this day-and-age of computer viruses, hacking, and governmental regulations, database security and auditing is a subject of paramount importance. And Ron Ben Natan's new book, Implementing Database Security and Auditing, attacks the subject with a vengenance.

In just over 400 pages the author manages to quite thoroughly cover a wide variety of database security topics. Whether you want to learn more about encryption, authentication and password control, or access control, this book provides help.

The book is useful for both DBAs and security administrators, giving each a better view of the world where the disciplines of database management and security management meet. Even better, the book offers many examples and guidelines for multiple environments. Whether you use DB2 on AIX, MySQL on Linux, Oracle on Unix, or SQL Server on Windows, Ben Natan's book provides useful guidance.

Are you curious to know more about SQL injection attacks? Learn what they are and why they are dangerous in this book. What about buffer overflows? Maybe you've read about them in the IT press, but those "newsy" pieces rarely delve into the depth required to understand and prevent attacks using these methods. This book offers that depth.

Chapter 7, "Using the Database to do Too Much," is particularly useful. In this chapter the author discusses some of the things not to do if you want to properly secure your database environment. You can save yourself a lot of trouble by reading and following these useful suggestions.

I think my favorite section of the book is the final three chapters. Here is where the author tackles the meaty topics of regulatory compliance and database auditing. New governmental rules and regulations are being introduced constantly and their impact on database administration is not clearly understood by many heads-down, techies. This book will give you a clearer understanding of laws such as GLB, Sarbanes-Oxley, and HIPAA -- and lend guidance on how to adapt your database environment in order to comply with these laws.

All-in-all Implementing Database Security and Auditing is a useful and timely publication that most DBAs would do well to read and embrace.

© 2005, Mullins Consulting, Inc.

Friday, July 22, 2005  |  Permalink |  Comments (0)
trackback URL:   http://www.dbazine.com/blogs/blog-cm/craigmullins/blogentry.2005-07-22.1376630476/sbtrackback
Craig Mullins
Data Management Specialist
Bio & Writings
Subscribe to my blog Subscribe to my blog
« February 2006 »
Su Mo Tu We Th Fr Sa
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28        
2006-02-01
19:35-19:35 Some of My Favorite Quotes
2006-02-04
22:09-22:09 Here We Go Steelers!
2006-02-07
18:14-18:14 More Details on IT Salaries
 
 

Powered by Plone