Solved

Securing SQL Server 2012

Posted on 2013-11-16
6
280 Views
Last Modified: 2013-11-22
Hey guys!!

I must secure a sqlserver database.  I've read quite a bit about certificates and key but being a newbie to security I'm lost.

I am using 2005 express and 2012 express.

Any help would certainly be appreciated.

Thanks,
Jerry
0
Comment
Question by:JDL129
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 11

Expert Comment

by:Gregory Miller
ID: 39653801
Securing the server can mean a lot of things. You mention certificates in your question which is really encryption, not really security. Are you trying to simply encrypt the database or are you trying to prevent access? Or both?
0
 

Author Comment

by:JDL129
ID: 39659374
Technodweeb!!!!!  Thanks for the post!!

My main goal is to prevent access to files with patient medical information that are contained in a sql server 2005 express database.  How would be the best way to go about it?

Sorry I'm late answering but the bank screwed up my account and EE was not able to process my payment.

Thanks again!!

Jerry
0
 
LVL 11

Expert Comment

by:Gregory Miller
ID: 39659890
With medical information you need to study up on HIPPA Compliance. I cannot advise you on this topic. As for good first steps to safeguard your data would be to store things that are sensitive in an encrypted fashion as you were speaking of initially.

For the best performance, you could encrypt the data before placing it into the data fields. This would happen on-the-fly and each computer in the network would never feel the performance hit. The other way to do it would be to encrypt the tables in the SQL database itself which will be a much bigger performance hit as every transaction would require an encryption or decryption process to occur. This requires Express 2005 or greater which you have. The only other option would be to encrypt the file system where the database files reside, but this will be even more of a performance hit as every filesystem read and write will be affected.
0
Online Training Solution

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action. Forget about retraining and skyrocket knowledge retention rates.

 

Author Comment

by:JDL129
ID: 39659934
Thanks for the post!!!!

How would I go about encrypting the data before placing it into the data fields and also how would I go about decrypting it when I read it back into the database.

THANKS!!!!

Jerry
0
 
LVL 11

Accepted Solution

by:
Gregory Miller earned 500 total points
ID: 39669178
That option would be useful to you if you were the developer of the application. Since you asked this question, I can assume that you are not the app developer.

So you are trying to prevent a person that might have copied the DB file from accessing the data within?

This means that you would need to use the methods found here:
http://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=2&sqi=2&ved=0CEYQFjAB&url=http%3A%2F%2Fdownload.microsoft.com%2Fdownload%2F4%2F7%2Fa%2F47a548b9-249e-484c-abd7-29f31282b04d%2FSQLEncryption.doc&ei=5HePUtzcEJDg2wXnwoAQ&usg=AFQjCNHkAVvzLfb_qaOaqJxvVNiQCqDcHg&sig2=U9lVlHLj8HZu7qyXISYF2w&bvm=bv.56988011,d.b2I&cad=rjt

I would make certain you have an excellent and verified backup before you do anything with encryption. One ooops factor will render your DB useless. Practice this process on a standalone instance, even on another machine or better yet, in a virtual machine, this way you can test and if it does not work you can rollback and do it again till you get it right.
0
 

Author Closing Comment

by:JDL129
ID: 39669513
WONDERFUL!!!
0

Featured Post

Transaction Monitoring Vs. Real User Monitoring

Synthetic Transaction Monitoring Vs. Real User Monitoring: When To Use Each Approach? In this article, we will discuss two major monitoring approaches: Synthetic Transaction and Real User Monitoring.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article we will learn how to fix  “Cannot install SQL Server 2014 Service Pack 2: Unable to install windows installer msi file” error ?
The conference as a whole was very interesting, although if one has to make a choice between this one and some others, you may want to check out the others.  This conference is aimed mainly at government agencies.  So it addresses the various compli…
Using examples as well as descriptions, and references to Books Online, show the documentation available for datatypes, explain the available data types and show how data can be passed into and out of variables.
Viewers will learn how to use the UPDATE and DELETE statements to change or remove existing data from their tables. Make a table: Update a specific column given a specific row using the UPDATE statement: Remove a set of values using the DELETE s…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question