1
Running Head: DATABASE SECURITY POLICY
Database Security Coding
Asha Varghese
Liberty University
Studies in Information Security, CSIS 340
October 9, 2018
2
DATABASE SECURITY POLICY
Database Security Coding for John Tech
Overview
Databases are what people use all the time in business. Databases are what people use to
store all kinds of information there. People store financial information and other things that are
related to their business there. John Tech stores all of it company information on the databases.
The security on databases needs to be more secure than ever before because of all the attacks that
have been on them. John Tech needs a list of credentials people who will have access to the
database. According to Bambara. A (2015), Databases have become more complex in the coming
days and they need more and more security. Databases have become more and more useful each
year with it able to store all the information that it can on there. There will be many people who
have the credentials to access the database but some of the credentials are fake that people right
down. People with good credentials will get hired because people with bad ones can lead to the
incorrect use of people storing data and getting all the information they need to access this
database. Also, if these people get hired and get access to the databases it will be bad for the
company because of what they could do to the database, and they can comprise the system and
they may have allowed the databases to be attacked. With all the technology upgrades that are
happening it is important to secure the data.
There needs to be a more secure way to be able to access this database and there is one
nowadays. There is a method called a one-time password to gain access to the databases.
According to Zhao and Luo (2017), to be able to access the database there need to be a password
for the user and a random number. These types of databases had become more secure than ever
because it will be hard for the attacker because of the one-time password and that is was made
because of a negative database. People needed to make sure that the database that they access
3
DATABASE SECURITY POLICY
can be secure form all point of entry, and it will be as soon as everything is secure and tight for
the people who will be able to access the database. The assets that are in the database is very
sensitives information. The data that is on these databases are all about the company financials
and client’s information. Securing the information that is on the database should be our number
one priority at John Tech. Compliance with the database security policy will help out in the long
run to securing a database.
Purpose
This policy is designed to make sure that the database is secure at John Tech. Also, this
policy is making sure that everyone at John Tech knows that the databases can be accessed by
certain people. It is what best for the company to have a more secure database. Also, many
people know what databases are used for it used to store data and information liked stated before.
Many people are now using a cloud for databases, but it can cause some concern for safety. A
cloud database is a database that runs on a cloud-based computer and it a service. According to
Song, Wang, Wang, Peng, & Lou (2017), storing data in a local database is different than storing
in the cloud database because it raises concern for privacy and safety. This is one of the many
reasons why John Tech store all of its data on local databases as opposed to cloud databases. The
purpose of storing all the data on these databases is to make sure that no one else has access to
what John Tech brings in. Many people go with cloud databases because of the low cuts but with
all of that in mind, it is better than John Tech store its data on local databases because of privacy
issues like stated before and it better even though it more expensive. As Ferretti, Marchetti,
Andreolini, & Colajanni (2018), said in their paper “Cloud database represents a great
opportunity for companies and organizations in terms of management and cost savings.” (p.
497). Many people can see that so many companies use databases now for all their business
4
DATABASE SECURITY POLICY
practices. As with any database this database needs to be secure by usernames and password for
people who are allowed access to the database.
Many people know what databases can do but some of these databases have servers on
them as well. They will be more secure than ever before and it is important that databases need
to more and more secure now than ever before like stated before. People run software
applications on these databases and the security on these databases needs to be tighter. The
purpose of this policies is to make sure that all the requirements for a strong database are met and
that it meets all the standards that are needed in order to have a good database.
General Objectives
At John Tech it is important that the database is secure and that only the people that allow
accessing the database are the only ones to use it. These people will be looking at carefully and
the people who are in charge will check the qualifications of these people to make sure that these
people are good enough to allow access to the database. Some systems allow only a couple of
users to access the database like Lin, & Lee (2014), who allows two users to store their data to a
secure database. Many companies like John Tech store all of its information on these databases
are they store money and contact information from their clients. People use databases for all sorts
of reasons and they do it within the time constrained. The people who are have authorized to
access this database may have to code the database. The credentials of the people who access the
database must be stored in a location that is safe. With all of the support and the requirements
that the database needs all the profits will be there. The objectives for this database are met with
the requirements which are the storage of the people who access the database with usernames
and passwords and making sure that the people who have access to the database have access to
them. Also, they make sure they do everything that is required of them. This policy will serve as
5
DATABASE SECURITY POLICY
a reminder to people who access the database to have good certifications. These credentials serve
a purpose for people who want to access the database but need certain requirements in order to
access the database and which is good for John tech. With all the attacks that have been
happening it is good to have people who people can trust.
Scope
This policy is for the people who have been given access to the database as well as other
people. People need to make sure that they know what they are doing and making sure
everything goes right because it can be a problem it is not. This policy will make sure that people
to know what is going on with the database. The database needs to be of a certain form and
coded just right for John Tech. This policy applied to all the people who have the right
credentials for a database. People with the right qualifications will know what to do inside the
database, and they will make sure everything is just right. Databases are really special for this
company because they just about store everything for this company. Databases are just what
many companies use now they need to be done right because all of the important data that belong
to the companies will be on there.
Policy Compliance
This policy will be done right and done correctly and because if it's not someone will be
fired. There are several compliances that need to be addressed and will be addressed in this
policy. The measurement of this policy will be consistent of what needs to be done in order to
make sure that people do with what they need to do in order to make sure that the policies are
safe and efficient. Some of these policies will have methods for doing things and will be done in
an orderly fashion. The people who will be making the database will fellows certain rules, and
making sure that everything about the database is met, and that the policy is met. They will make
6
DATABASE SECURITY POLICY
sure that the owners know what they need to do to make sure that the police is equipped. Plus,
they making sure that it is ok with all the compliances that are being made with the policies.
There are several needs that need to be met with this policy. All of the expectations to the
policy will be met by someone whose know the database field. Almost all of what people know
about databases is what they learn from high school and all bit of college. People store databases
in excel but some people store in Microsoft Access which is better than excels. A lot of the
databases now have several coding languages to them that John Tech is also allowing people
with programming background have access to the database. The compliance rules are that if
anyone is found violated this policy they will be fired. Any code that is violated with this policy
will be removed within a 30 day period. People need to be careful with this policy because it
could mean their careers.
Finding
According to Attila Altay Yavuz (2018), some databases outsource their data
management to outside providers. Some of these databases go to the outer sources, and they
offload the data that they have and store it there. A lot of the research that people finds out about
these databases are all about in the biofield. The medical field uses databases for all sorts of
things. One of them is for Addiction and some of this addiction does not have a database because
they have not for have not been developed yet one example of this according to Choi, Kim, Lee,
Jang, Kim, Choi (2016), is Internet Addiction. A lot of these databases have some sort of seal to
them to make it secure.
The databases are to be handled carefully and they are a lot of research to the databases in
the medical field like stated before. Plus with the use of cloud databases, more people are using
that over local databases in the medical field. Also, according to Ferrtti et al. (2018) cloud
7
DATABASE SECURITY POLICY
database represents an important opportunity for organizations that attracted by high availability.
These databases need to be secured by database specialists. All of these databases do have
security concern and they need to be met with.
Related Standard
The security policy of databases is found with password policy which it was written
before. There are people who are in charge of the company are looking into people who access
the databases and they are making sure that what they do inside the company is done right. They
do this because they are part of the company and it the company reputation that is at stake if they
do things the wrong way. There are many different things that need to be taken care of in order
for the database to be secure like stated before. People with access to the database will follow the
rules that are made up by the owner of John Tech. These rules will help with to make sure that
the people are accessing the database to do what the boss wants them to do.
Username and Passwords
The username and passwords need to be the consistency of the group of letters and
characters. As said beforehand people with a negative database have the one-time password
which can help to prevents attacks. Recovering an original database is a hard job and it will take
time to recover it (Luo & Zhao, 2017). Sometimes it ever harder to secure these databases but it
needs to be done. So in order to have these databases secure the people who are authorized need
to have a good and strong username and password because the people who are in charge will
look at it and make sure that it is right.
Definitions
Credentials- a list of qualification for a specific job
Authorization- someone who has permission from above
8
DATABASE SECURITY POLICY
Terms
The people who have been given access to the databases have all the recommendations
they need in order to be given access to the database. People with the authorization to access the
database have specific rules that need to follow like stated before. In order to do the right thing,
people will make sure they get the job is done right by going over it a couple of times and
making sure that the job is done right from the start. John Tech will make sure all the credentials
that people need in order to access the database is good like stated before. They will make sure
the job is done that is good, and they will follow the rules because if they don't comply with the
rules they will be fired from the job. So these people will make sure that everything is met and
required or it will cost them the job.
Summary
This policy was to make sure that the people who handle the database know what needs
to get done and who can access it. There have been many researchers that have looked into
databases and did a paper on it. People have seen from the research that has been done and there
is more than one kind of databases and that is a cloud database. Cloud databases are what most
people are using now. This policy is strong because it is the first step to make sure that all the
requirements are met to making sure that John tech has a good and strong database. People with
good qualifications are the only ones who can have access to the database. All the database need
to have a good and strong usernames and password to get into the databases. All the people who
are allowed access have been given authorized by the owner and that person have reviewed all
the credentials of the people who have been given access. John Tech will have a strong and
secure database that will help with everything because of these people.
9
DATABASE SECURITY POLICY
References
Bamrara, A. (2015). Evaluating database security and cyber attacks: A relational approach.
Journal of Internet Banking and Commerce, 20(2), 1-17: Retrieved from
http://ezproxy.liberty.edu/login?url=https://search-proquest-
com.ezproxy.liberty.edu/docview/1799378132?accountid=12085
Jeongseok Choi, J. K.-J. (2016). The OAuth 2.0 Web Authorization Protocol for the Internet
Addiction Bioinformatics (IA) Database. Genomics & Informatics, 14(1):20-28: DOI
10.5808/GI.2016.14.1.20
Luca Ferretti, M. M. (2018). Asymmetric cryptographic scheme for data integrity verification in
cloud databases. Information Sciences 422, 497-515:
https://doi.org/10.1016/j.ins.2017.09.033
Luo, D. Z. (2017). One-time password authentication scheme based on the negative database.
Engineering Applications of Artificial Intelligence 62, 396-404:
https://doi.org/10.1016/j.engappai.2016.11.009
Tsung-Hung Lin, T.-F. L. (2014). Secure Verifier-Based Three-Party Authentication Schemes
without Server Public Keys for Data Exchange in Telecare Medicine Information
Systems. Journal of Medical Systems 38: 30: https://doi-
org.ezproxy.liberty.edu/10.1007/s10916-014-0030-4
Wei Song, B. W. (2017). Tell me the truth: Practically public authentication for outsourced
databases with multi-user modification. Information Sciences 387, 221-237:
https://doi.org/10.1016/j.ins.2016.07.031
Yavuz, A. A. (2018). Immutable Authentication and Integrity Schemes for Outsourced Databases.
IEEE Xplore Digital Library 15 : DOI: 10.1109/TDSC.2016.2530708
10
DATABASE SECURITY POLICY