Implementing Database Security and Auditing
Autor Ron Ben Natanen Limba Engleză Paperback – 19 mai 2005
* Useful to the database administrator and/or security administrator - regardless of the precise database vendor (or vendors) that you are using within your organization.
* Has a large number of examples - examples that pertain to Oracle, SQL Server, DB2, Sybase and even MySQL..
* Many of the techniques you will see in this book will never be described in a manual or a book that is devoted to a certain database product.
* Addressing complex issues must take into account more than just the database and focusing on capabilities that are provided only by the database vendor is not always enough. This book offers a broader view of the database environment - which is not dependent on the database platform - a view that is important to ensure good database security.
Preț: 534.72 lei
Preț vechi: 668.40 lei
-20% Nou
Puncte Express: 802
Preț estimativ în valută:
102.34€ • 107.96$ • 85.28£
102.34€ • 107.96$ • 85.28£
Carte tipărită la comandă
Livrare economică 02-16 ianuarie 25
Preluare comenzi: 021 569.72.76
Specificații
ISBN-13: 9781555583347
ISBN-10: 1555583342
Pagini: 432
Dimensiuni: 191 x 235 x 28 mm
Greutate: 0.74 kg
Editura: ELSEVIER SCIENCE
ISBN-10: 1555583342
Pagini: 432
Dimensiuni: 191 x 235 x 28 mm
Greutate: 0.74 kg
Editura: ELSEVIER SCIENCE
Public țintă
* Information Security Officers, security administrators and auditors - defining, implementing and enforcing security and audit policies and methods.* DBAs - tasked with securing the database environment, setting up user and application access to the database, setting up database access policies, auditing data access etc.
* Application developers - designing and developing security features for applications
* Operations groups - implementing and administering application environments (both custom and off-the-shelf suites).
Cuprins
Preface
1. Getting Started
2. Database Security within the General Security
Landscape and a Defense-in-Depth Strategy
3. The Database as a Networked Server
4. Authentication and Password Security
5. Application Security
6. Using Granular Access Control
7. Using the Database To Do Too Much
8. Securing database-to-database communications
9. Trojans
10. Encryption
11. Regulations and Compliance
12. Auditing Categories
13. Auditing Architectures
Index
1. Getting Started
2. Database Security within the General Security
Landscape and a Defense-in-Depth Strategy
3. The Database as a Networked Server
4. Authentication and Password Security
5. Application Security
6. Using Granular Access Control
7. Using the Database To Do Too Much
8. Securing database-to-database communications
9. Trojans
10. Encryption
11. Regulations and Compliance
12. Auditing Categories
13. Auditing Architectures
Index
Recenzii
"It's
been
said
that
everyone
has
their
15
minutes
of
fame.
You
certainly
don't
want
to
gain
yours
by
allowing
a
security
breach
in
your
database
environment
or
being
the
unfortunate
victim
of
one.
Information
and
Data
are
the
currency
of
On
Demand
computing,
and
protecting
their
integrity
and
security
has
never
been
more
important.
Ron's
book
should
be
compulsory
reading
for
managing
and
maintaining
a
secure
database
environment."
Bob
Picciano,
VP
Database
Servers,
IBM.
"Today, databases house our 'information crown jewels', but database security is one of the weakest areas of most information security programs. With this excellent book, Ben-Natan empowers you to close this database security gap and raise your database security bar!" Bruce W. Moulton. CISO/VP, Fidelity Investments (1995 - 2001)
"Let's start with a simple truth about today's world: If you have a database and you make it available to customers, employees, or whomever over a network, that database will be attacked by hackers -- probably sooner rather than later. If you are responsible for that database's security, then you need to read this book. No other single source covers all of the many disciplines and layers involved in protecting exposed databases, and it especially shines in synthesizing all of its concepts and strategies into very practical and specific checklists of things you need to do. I've been an Oracle DBA for 15 years, but I'm not embarrassed to admit that five minutes into Chapter One I was making notes on simple measures I had overlooked." -- Charles McClain, Senior Oracle DBA, North River Consulting, Inc.
"In just over 400 pages the author manages to quite thoroughly cover a wide variety of database security topics. Whether you want to learn more about encryption, authentication and password control, or access control, this book provides help." - dbazine.com, Craig Mullins
"I learned some new information that I would not have known if I hadn't been exposed to it by this book." - C.J. KellyComputerworld
"Today, databases house our 'information crown jewels', but database security is one of the weakest areas of most information security programs. With this excellent book, Ben-Natan empowers you to close this database security gap and raise your database security bar!" Bruce W. Moulton. CISO/VP, Fidelity Investments (1995 - 2001)
"Let's start with a simple truth about today's world: If you have a database and you make it available to customers, employees, or whomever over a network, that database will be attacked by hackers -- probably sooner rather than later. If you are responsible for that database's security, then you need to read this book. No other single source covers all of the many disciplines and layers involved in protecting exposed databases, and it especially shines in synthesizing all of its concepts and strategies into very practical and specific checklists of things you need to do. I've been an Oracle DBA for 15 years, but I'm not embarrassed to admit that five minutes into Chapter One I was making notes on simple measures I had overlooked." -- Charles McClain, Senior Oracle DBA, North River Consulting, Inc.
"In just over 400 pages the author manages to quite thoroughly cover a wide variety of database security topics. Whether you want to learn more about encryption, authentication and password control, or access control, this book provides help." - dbazine.com, Craig Mullins
"I learned some new information that I would not have known if I hadn't been exposed to it by this book." - C.J. KellyComputerworld