SQLServerCentral is supported by Red Gate Software Ltd.
 
Log in  ::  Register  ::  Not logged in
 
 
 

It's Time for Encryption

By Andy Warren, 2009/11/03

Total article views: 100 | Views in the last 30 days: 4

http://rfayoumi.files.wordpress.com/2007/11/encryption.png?w=206&h=199Imagine withdrawing your life savings and putting into a bomb proof container, and that the container only had one key. If the key was lost you would also lose your life savings. It’s scary to downright frightening to think that something so easy to lose could in turn cause you to lose everything. On the other hand, imagine withdrawing your life savings and putting into a very secure room; stout doors, good locks, cameras recording everything, and only a few people you trust have access to the room. Which is the safer and more secure alternative? Not a simple question is it?

Maybe those aren't the best examples, but I think you know what I mean - fear has been the biggest hurdle to adoption of encryption as a routine security measure for databases. We fear the loss of keys, the loss of performance, and the loss of simplicity once we add encryption to our already complex environments. We've grown comfortable with the idea that with our servers in 'ring zero' there is little chance of the machines being compromised.

But, imagine the worst happens and someone breaches the server room and takes drives or tapes containing sensitive data. Is it enough to say that we locked the door every night, or will people ask if there was more we could have done?

I think database security is a lot like home security. We take the precautions that we can afford, stick to, and that make sense given the environment and the value of the items we want to protect. With the addition of transparent data encryption (TDE) in SQL 2008 I think we've reached the tipping point where we as DBA's should declare ALL data as sensitive and encrypt it all. It's in the box, it's relatively easy to use, and once applied doesn't demand a lot of attention from us.

By Andy Warren, 2009/11/03

Total article views: 100 | Views in the last 30 days: 4
Your response
 
 
Related Articles
FORUM

sql 2005 encryption

encryption

FORUM
ARTICLE

Protecting the Encryption Keys

When you deal with encryption in your database, Steve Jones thinks you add a layer of complexity to ...

ARTICLE

Free Encryption

Free SQL Server 2000 Encryption for your data!!! Author Michael Coles has put together a tolljit and...

ARTICLE

Encrypting Data

Encrypting data is the easy part of dealing with encryption and databases. Steve Jones talks about s...

Tags
editorial    
encryption    
 
Contribute

Free registration required...

To read the rest of this article, and access thousands of other articles, we ask you to register on the site and subscribe to our newsletters.

Login (existing users)

Login

Email:   Password:   Remember me: Forgotten your password?

Register (new users)

Register

Email:   Password:
Confirm:

Subscribing to our newsletters gets you:

  • ALL of our content (thousands of articles, scripts, and forum postings)
  • A daily newsletter (example)
  • A weekly news round up (example)
  • The opportunity to ask and answer questions in our forums
  • A daily Question of the Day to test and help you increase your knowledge of SQL Server.

Steve Jones
Editor, SQLServerCentral.com