Av rating:
Total votes: 5
Total comments: 0


John Magnabosco
Protecting SQL Server Data
20 August 2009

"Privacy is not something that I'm merely entitled to, it's an absolute prerequisite". – Marlon Brando

The battle to secure sensitive personal and business data is a tough one, and the consequences of mishandling sensitive data can be severe. Even more damaging than the lawsuits and fines that can result from regulatory non-compliance is the loss of customer confidence resulting from breaches of security. SQL Server's encryption features, when properly planned and implemented, as described in this book, are an essential tool in the DBA's fight to safeguard this data.

Download Protecting SQL Server Data (Free 220-page eBook)

Printed Book: $29.99

Table of Contents

  • Chapter 01: Understanding Sensitive Data
  • Chapter 02: Data Classification and Roles
  • Chapter 03: Schema Architecture Strategies
  • Chapter 04: Encryption Basics for SQL Server
  • Chapter 05: Cell-level Encryption
  • Chapter 06: Transparent Data Encryption
  • Chapter 07: One-way Encryption
  • Chapter 08: Obfuscation
  • Chapter 09: HoneyCombing a Database
  • Chapter 10: Layering Solutions
  • Appendix A: Views and Functions Reference
  • Appendix B: The HomeLending Database

Why read this book?

For as long as there has been something to communicate between two persons there has been data. Today, vast volumes of it are gathered about almost every individual and business. It is the information that we provide when we sign up for an account at our favorite website, fill out a job application, or apply for a mortgage.

These valuable, often sensitive, data assets are stored in a SQL Server database, and entrusted to the Database Administrator, who must use every weapon and strategy at his or her disposal in the "war" to protect this sensitive data from would-be hackers, phishers, rumor mongers and identity thieves. Encryption is one of the primary weapons with which this battle can be won, and yet it is treated with trepidation by many, who fear that it will prove "just another way for data to be lost" or "an unjustifiable cost on performance".

This book holds the key to "encryption without fear". In it, the author goes way beyond the usual demonstration of the SQL Server cryptographic functions. He explains how to assess and categorize data elements according to sensitivity, regulate access to the various categories of data using database roles, views and stored procedures, and then how to implement an efficient and secure data architecture using the available SQL encryption features, such as cell-level encryption, transparent data encryption and one-way encryption.

At each stage the author covers not only how the features work, but also described the situations when they are and are not suitable, and at all times stresses the steps that must be taken to ensure that the solution is maintainable.



This article has been viewed 2673 times.
John Magnabosco

Author profile: John Magnabosco

John Magnabosco is a writer and a SQL Server Database Consultant. He is also the current President and Co-Founder of the Indianapolis Professional Association for SQL Server (IndyPASS) as well as the Speaker Coordinator and Co-Founder of IndyTechFest. As a database developer and administrator John has had the opportunity to work on databases as small as single user systems and as large as a terabyte enterprise databases in the banking and government arenas.

Search for other articles by John Magnabosco

Rate this article:   Avg rating: from a total of 5 votes.


Poor

OK

Good

Great

Must read
 
Have Your Say
Do you have an opinion on this article? Then add your comment below:
You must be logged in to post to this forum

Click here to log in.
 



recommended site pinvoke

PInvoke.net is a user-driven wiki which provides .NET developers with native method signatures, so they don't have to spend time writing them from scratch.




.NET Performance Testing and Optimization - Part 1: Building your test rig
 Paul's Guide to getting started with .NET Performance Profiling is a comprehensive and essential... Read more...

Don't Just Roll the Dice - eBook Download
 Neil Davidson has created a short handbook with the theory, practical advice and case studies, to... Read more...

Don't Just Roll The Dice
 Neil Davidson has created a short handbook with the theory, practical advice and case studies, to... Read more...

How to Become an Exceptional DBA, 2nd Edition
 A 2nd edition of Brad McGehee’s popular "career guide" for DBAs, designed to help new and prospective... Read more...

The Art of XSD
 When information is exchanged in XML format, you need an agreement between the sender and receiver... Read more...

Exchange 2010 - A Practical Approach
 Jaap's Practical Guide to Exchange Server 2010 draws upon all that experience to deliver an easy-to-use... Read more...

Exchange 2010 - A Practical Approach
 Jaap's Practical Guide to Exchange Server 2010 draws upon all that experience to deliver an easy-to-use... Read more...

Brad's Sure Guide to SQL Server Maintenance Plans
 Brad's Sure Guide to Maintenance Plans shows you how to use the Maintenance Plan Wizard and Designer to... Read more...

Protecting SQL Server Data
 John Magnabosco's excllent new book, "Protecting SQL Server Data", holds the key to encryption without... Read more...

SQL Server Tacklebox
 Inside the SQL Server Tacklebox you'll find day-to-day tools, scripts and techniques to automate and... Read more...

Over 150,000 Microsoft professionals subscribe to the Simple-Talk technical journal. Join today, it's fast, simple, free and secure.

Join Simple Talk