SQL Clone
SQLServerCentral is supported by Redgate
Log in  ::  Register  ::  Not logged in

Is There Interest in SQL Server Security Pre-Cons?

I’m very passionate about security, especially database security. As the numbers with regards to data breaches continue to climb, this is become even more important to me. I’ve been affected personally by data breaches, as have many others. For instance, I’ve had to change out my credit cards due to payment processor breaches, I was affected by the South Carolina Department of Revenue breach, and I’m sure there are others, maybe ones that weren’t reported, that I was affected by as well. I enjoy speaking on security, but a 45-75 minute session barely scratches the surface when it comes to any security topic. I’d love to spend more time covering more information, diving down into more details, etc., for those wanting to learn. The best way to do that is probably through a pre-con at a SQL Saturday. I’ve given half day and full day sessions before, primarily to IT auditors, and I’m thinking the same sort of time length is appropriate to convey enough information to make it worth paying for. Here’s a sample agenda from one of my half day courses to give you an idea of what I’m thinking about (this is from a SQL 2000-2008R2 class):

  • Hour 1
    • General Security Principles We Follow
    • Hardening OS and SQL Server – Surface Area
    • Access SQL Server and its Databases
  • Hour 2
    • SQL Server’s Permission Model
    • Changes from SQL Server 2000 to 2005
  • Hour 3
    • Auditing using Triggers
    • Server Side Traces
    • Audit Object
  • Hour 4
    • Built-In Encryption Options

If you think you’d be interested in such a pre-con, especially if you’re a SQL Saturday organizer, comment on this post or, better, send me an email at brian {dot} kelley {at} sqlpass {dot} org (note the spelling on the last name as kelly will cause it to bounce).

K. Brian Kelley - Databases, Infrastructure, and Security

IT Security, MySQL, Perl, SQL Server, and Windows technologies.


Posted by apatel 10847 on 5 November 2013

I would be interested.

Posted by bscurlock on 5 November 2013

This sounds like a great idea for SQL saturday, maybe even a full day pre-con at PASS Summit?

Posted by Barry Slagle on 5 November 2013

I'm on board.

Posted by SQLServerCentral 63253 on 5 November 2013

That sounds great!

Posted by Knowledge Draftsman on 5 November 2013

Sounds great.

Posted by opc.three on 5 November 2013

Great idea. It's a topic that is arguably covered far less often than it should be covered. Please try to make the attendees aware of all the ways a member of the sysadmin Role can achieve identity-obfuscation by taking on the identity of the SQL Server service account via xp_cmdshell and other T-SQL features that can interact with the host OS.

Leave a Comment

Please register or log in to leave a comment.