?
Solved

Database security in cloud

Posted on 2013-01-18
8
Medium Priority
?
435 Views
Last Modified: 2014-11-12
Hello...

I have a database and web server and i need to host them in the cloud, each on a sparate server.

What is the most secure scenario I can get from the could to host eh DB? it is critical and needed to be secure.

Thanks in advance!
0
Comment
Question by:Suliman Abu Kharroub
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
8 Comments
 
LVL 75

Accepted Solution

by:
Aneesh Retnakaran earned 800 total points
ID: 38795001
Hosting on cloud is like hosting on a single VM server which is dedicated to your application
0
 
LVL 23

Author Comment

by:Suliman Abu Kharroub
ID: 38795009
Thank you for your input...

So, is it secure to host eh DB on the cloud ? like EC2.

Do I have an options to a security  layer on the could ?
0
 
LVL 14

Assisted Solution

by:Schnell Solutions
Schnell Solutions earned 800 total points
ID: 38795013
The security is going to be tied to the provider giving you the cloud solution. For example Microsoft is a very trusted company, they have a service called "Azure", you can search about it. The idea with this service is that you can rent virtual machines in the cloud with a very high availability and security
0
Bringing Advanced Authentication to the SMB Market

WatchGuard announces the acquisition of advanced authentication provider, Datablink, with one mission – to bring secure authentication to SMB, mid-market, and distributed enterprises with a cloud-based solution, ideal for resale via their established channel & MSSP community.

 
LVL 23

Author Comment

by:Suliman Abu Kharroub
ID: 38795035
I am reading about it...

Thanks again.
0
 
LVL 33

Assisted Solution

by:shalomc
shalomc earned 400 total points
ID: 38798228
there are 2 basic security areas that make a cloud based database different from an on-site db.

The first one is involving the providers' personnel and infractructure. You want a hosting provider/ cloud provider that adheres to strict security regulations like ISO 27001 or equivalent.

The other one is about the tools, like firewalls,  that you get to secure access to your database. For example, can you manage network access from the internet and the datacenter and limit it only to what you define?

EC2 meets both requirements, and so does Azure.
0
 
LVL 23

Author Closing Comment

by:Suliman Abu Kharroub
ID: 38816926
Thanks all!
0
 
LVL 23

Author Comment

by:Suliman Abu Kharroub
ID: 38821143
Dears,

Can someone help me to understand one more question: what will happen for the DB instance and web instance when the physical or virtual machine require restart for windows update installation ? it will reboot automatically ? and how often ?


If its necessary to post this question on a new tried please advise.

Thanks all,
0
 
LVL 33

Expert Comment

by:shalomc
ID: 38821708
Please post a new question.

It production environments, it is not recommended to define windows update on autopilot.
The decision of when to update should be a conscious decision.

Being in the cloud really simplifies life for updating and patching. Remember, a new server instance costs very little to test for a few hours.
You should have an up to date images of your servers, so you just fire up a new instance of your application, patch it, test it, create a patched image, and roll over with very little disruption. If you have load balancers (like Amazon ELB) you can have zero disruption.

Microsoft has Azure SQL and amazon has RDS which are Databases as a Service that are maintained updated and patched by the vendor, so look into them too.
0

Featured Post

Interactive Way of Training for the AWS CSA Exam

An interactive way of learning that will help you visualize core concepts so that you can be more effective when taking your AWS certification exam.  Built for students by a student to help them understand the concepts that they are being taught.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently we ran in to an issue while running some SQL jobs where we were trying to process the cubes.  We got an error saying failure stating 'NT SERVICE\SQLSERVERAGENT does not have access to Analysis Services. So this is a way to automate that wit…
You deserve ‘straight talk’ from your cloud provider about your risk, your costs, security, uptime and the processes that are in place to protect your mission-critical applications.
Via a live example, show how to shrink a transaction log file down to a reasonable size.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question