InvestorsHub Logo
Followers 3
Posts 555
Boards Moderated 0
Alias Born 07/31/2003

Re: None

Thursday, 10/27/2005 1:55:22 AM

Thursday, October 27, 2005 1:55:22 AM

Post# of 249238
New Data Security with SQL Server 2005
http://www.theserverside.net/news/thread.tss?thread_id=37294

Posted by: Paul Ballard on October 26, 2005 @ 03:39 PM
Microsoft has released a new Technical White Paper on using SQL Server 2005 Encryption to secure important data. The document is based on Microsoft's own internal usage of encrypted SQL Server including meeting mandated regulatory statutes, sample implementations, and best practices for key management.

This document shares Microsoft IT experiences with these security strategies and with SQL Server 2005 encryption capabilities. Because many SQL Server 2005 pilot projects are currently in progress, Microsoft IT has learned valuable lessons and best practices that relate to data consolidation and encryption in the Microsoft IT LOB application space. Because Microsoft IT requirements are among the most challenging in the world, the strategies that Microsoft IT develops and the lessons that Microsoft IT learns through the deployment of SQL Server 2005 should provide meaningful guidance to corporations that want to deploy a SQL Server 2005–based encryption and key management framework.
After a brief executive introduction the paper outlines the regulatory compliance required for data storage including Sarbanes-Oxley, HIPAA, etc. It then provides an overview of encryption such as symmetric, asymmetric, and hybrid.

The paper then describes the application environment for three separate database systems implemented with SQL Server 2005 encryption including a description of SQL Server 2005's encryption capabilities.
SQL Server 2005 includes many security-related features that help protect the data in an organization. SQL Server 2005 includes password policy enforcement, a strong authentication functionality, and a granular hierarchical permissions model. SQL Server 2005 also includes a built-in data encryption capability. This column-level encryption capability is enhanced by an integrated and hierarchical infrastructure for managing encryption keys. Built-in encryption functions and application programming interfaces (APIs) make it easier for an organization to create an encryption security framework.

dude_danny

Join the InvestorsHub Community

Register for free to join our community of investors and share your ideas. You will also get access to streaming quotes, interactive charts, trades, portfolio, live options flow and more tools.