11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Checklist: Securing Your Database Server 733SQL Server Database ObjectsCheck DescriptionSample databases (including Pubs <strong>and</strong> Northwind) are removed.Stored procedures <strong>and</strong> extended stored procedures are secured.Access to cmdExec is restricted to members of the sysadmin role.Additional ConsiderationsCheck DescriptionA certificate is installed on the database server to support SSL communication <strong>and</strong> theautomatic encryption of SQL account credentials (optional).NTLM version 2 is enabled by setting LMCompatibilityLevel to 5.Staying SecureCheck DescriptionRegular backups are performed.Group membership is audited.Audit logs are regularly monitored.<strong>Security</strong> assessments are regularly performed.You subscribe to SQL security bulletins at http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/current.asp?productid=30&servicepackid=0.You subscribe to the Microsoft <strong>Security</strong> Notification Service at http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/notify.asp.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!