1 / 6100%
Proverbs 2:11 (NIV) -- “Discretion will protect you, and understanding will guard you.”
Proverbs 25:28 (NIV) -- “Like a city whose walls are broken down is a man who lacks
self-control.”
The topic of security should not be taken lightly considering a database is the primary
location of sensitive data in an enterprise. The article, “Database Security: What Students
Need to Know,” found in the Learn section, presents an outline of important database
topics. Provide a description of 2 of these topics and support your findings with additional
scholarly sources.
Discuss a recent business database security breach, the root cause of the breach, and
possible steps that could be taken to avoid future occurrences.
CSIS 525
DISCUSSION ASSIGNMENT INSTRUCTIONS
The student will complete 5 Discussions in this course. The student will post one thread of at
least 400500 words by 11:59 p.m. (ET) on Thursday of the assigned Module: Week. The
student must then post 2 replies of at least 200 250 words by 11:59 p.m. (ET) on Sunday of the
assigned Module: Week. For each thread, students must support their assertions with at least 4
citations in APA format. Each reply must incorporate at least 2 citations in APA format.
Acceptable sources include peer-reviewed journal articles, books, the course textbook, and the
Bible.
1
Discussion Thread
Student’s Name
Institutional Affiliation
Instructor
Course
Date
2
Database Security: What Students Need to Know topics
Access Control
Access Control is one of the methodologies organizations employ to ensure that only
authorized users have access to sensitive data belonging to a particular organization. Essentially,
it involves authentication and authorization. Database system utilizes various authentication
methods such as passwords. When a data breach occurs in a particular organization, one of the
things which are investigated is access control policies. There are four primary access control
models: MAC, RBAC, DAC, and Rule-Based Access Control (Mudarri et al., 2015; Coffin
Murray, 2010). There are numerous physical access controls such as Door security, Paper access
logs, Mantraps, and Video surveillance.
Database Vulnerability
It is vital to note that security vulnerabilities have been on the rise in the recent past.
Essentially, there has been an increase in a database breach. SQL injection is one of the most
common database security issues; through this method, malicious individuals can access
sensitive data from a particular database. Additionally, hackers have unlimited access, affecting a
particular organization negatively. There are other database vulnerabilities such as having weak
passwords, extensive user privileges, therefore, threatening data security, poor encryption,
Denial-of-service Attacks, and using outdated tools for data protection. Software errors also
cause some of the database security vulnerabilities witnessed in an organization (Hashim, 2018,
118). It is vital to address all these vulnerabilities to achieve maximum security.
Business database security breach
3
One of the recent data breaches of 2022 is the Baptist Medical Center data breach.
Essentially, unauthorized individuals were able to access the institution's computer network by
installing malicious codes (JD Supra, LLC, 2022). Some of the data that was compromised
through this attack includes people's names, addresses, information about health insurance,
people social security numbers, and patients' medical information. On June 16, this year, people
who were affected by the data breach were sent letters (JD Supra, LLC, 2022). In Texas alone,
the data breach report indicates that approximately 1.2 million patients were affected (JD Supra,
LLC, 2022). One of the ways the institution responded to the situation was by suspending the
affected systems.
Essentially, the organization confirmed that an unauthorized 3rd party accessed its
systems, thus removing data from the network. Various steps can be followed to avoid future
data security breaches. Some steps include employee cybersecurity training, updating software
regularly, having an effective cyber breach response plan, limiting a particular organization's
access to sensitive data, encrypting sensitive data, and trustworthy third-party vendors. Hackers
who conduct healthcare data breaches steal sensitive information belonging to people and sell
this information to third parties. Data breaches are here to stay, and organizations should ensure
that they implement the necessary measures to protect their customers' data from malicious
people.
4
References
Coffin Murray, M. (2010). Database security: What students need to know. Journal of
Information Technology Education: Innovations in Practice, 9, 061-077.
https://doi.org/10.28945/1132
Hashim, H. B. (2018). Challenges and security vulnerabilities to impact on database systems. Al-
Mustansiriyah Journal of Science, 29(2), 117-125.
https://doi.org/10.23851/mjs.v29i2.332
JD Supra, LLC. (2022). Baptist Health System Announces Data Breach Affecting Patients of
Two San Antonio-Area Hospitals. https://www.jdsupra.com/legalnews/baptist-health-
system-announces-data-7151699/
Mudarri, T., Abdo, S., & Al-Rabeei, S. (2015). SECURITY FUNDAMENTALS: ACCESS
CONTROL MODELS.
https://www.researchgate.net/publication/282219117_SECURITY_FUNDAMENTALS_
ACCESS_CONTROL_MODELS
Students also viewed