Database Security: Hardening, Encryption, Access Control and Auditing
Plan database security across PostgreSQL, MySQL, SQL Server, Oracle, MongoDB and MariaDB using network isolation, TLS, at-rest encryption, RBAC, auditing, secrets and backup security.
What does this guide solve?
Database security is more than password policy. Network, identity, least privilege, encryption, auditing, OS hardening, patching, secret management and backup security must work together.
Network isolation
Do not expose database ports directly to the internet; use application subnets/VLANs, firewalls/security groups and VPN/bastion layers.
Separate management access from application traffic where practical.
Authentication and authorization
Use named identities, role-based permissions and least privilege instead of shared administrator accounts.
Store service credentials in vault/secret-management systems rather than source code or configuration repositories.
TLS and encryption at rest
Protect client-server traffic with TLS and evaluate engine-supported TDE/tablespace/storage encryption for sensitive data.
Keep encryption keys in a separate security domain and test key rotation and recovery procedures.
Auditing and monitoring
Audit failed logins, privilege changes, schema changes, administrative activity and sensitive-data access according to risk.
Forward audit logs to independent central logging/SIEM.
Patching and backup security
Manage database engine, OS, drivers/clients and backup agents as one patch surface.
Separate backup-repository credentials, use immutable/offsite copies and perform restore tests.
Frequently Asked Questions
Is changing the database port enough?
No. Port changes are not a primary security control; use network isolation, firewalls and strong authentication.
Does TDE make a database completely secure?
No. TDE reduces storage-theft risk; application compromise, credential theft and authorised misuse require other controls.
Why should backup use separate credentials?
Separating privilege domains reduces the chance that a production compromise can also delete or encrypt backups.
Official technical sources
- https://www.postgresql.org/docs/current/security.html
- https://dev.mysql.com/doc/refman/8.4/en/security.html
- https://learn.microsoft.com/sql/relational-databases/security/
- https://docs.oracle.com/en/database/oracle/oracle-database/23/dbseg/
- https://www.mongodb.com/docs/manual/security/
- https://mariadb.com/docs/server/security/
Evaluate Your Database Infrastructure
We can review workload, security, hardware, HA and backup requirements together.