11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Checklist:Securing Your Database ServerHow to Use This ChecklistThis checklist is a companion to Chapter 18, “Securing Your Database Server.” Use itto help you secure a database server <strong>and</strong> also as a snapshot of the correspondingchapter.Installation Considerations for Production ServersCheck DescriptionUpgrade tools, debug symbols, replication support, books online, <strong>and</strong> development tools arenot installed on the production server.Microsoft ®SQL Server is not installed on a domain controller.SQL Server Agent is not installed if it is not being used by any application.SQL Server is installed on a dedicated database server.SQL Server is installed on an NTFS partition.Windows Authentication mode is selected unless SQL Server Authentication is specificallyrequired, in which case Mixed Mode is selected.A strong password is applied for the sa account or any other member of the sysadmin role.(Use strong passwords for all accounts.)The database server is physically secured.Patches <strong>and</strong> UpdatesCheck DescriptionThe latest service packs <strong>and</strong> patches have been applied for SQL Server.(See http://support.microsoft.com/default.aspx?scid=kb;EN-US;290211.)Post service-pack patches have been applied for SQL server.(See http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/current.asp?productid=30&servicepackid=0.)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!