For Lady Hawkins only

0 comments

Through this real-world project you will design a secure, scalable, and responsive database security plan and requirements definition document for a system of your choice. Your chief security officer has given you the assignment of defining, developing, and documenting a database security policy and plan for your databases. This document shall define who is responsible for security in your organization and what authority is granted to that person in the advent of a security breach. Additionally, policies and procedures should be defined and documented that outline the daily administrative tasks, definition of security rules and methods, and the enforcement of those rules. Your job is not to implement the requirements but to define what the requirements are and to document them. While working on your project, assume the roles of the chief security officer, database designer, database administrator, and chief applications designer.

Guidelines

Back to Top

Each week you should add analysis and design elements to your project by following and extending the topics discussed in class. Plan to develop your project using a single Microsoft Word document. The format will be discussed in class. In addition, you should be prepared to share your project’s status and issues each week in class.

The final version of your project must be posted to the Dropbox. Here is a step-by-step outline to aid you in completing your project. Feel free to propose modifications that may better suit your specific goals.

Below is the key schedule for the applied research project:

Week 1: Class discussion of applied research project.
Week 2: The research project abstract is due at the end of this week.
Week 7: Applied research project report submission.

Part 1: Project Identification and Business Environment — 20 points

Address the following topics as they apply to your policy:

  1. Establish authorities and responsibilities for database security management.
  2. Develop operational and incident management procedures when security breaches are discovered.
  3. Define personnel and procedures for daily administration and maintenance of security policies.

Part 2: Architecture and Operating System Considerations — 20 points

Address the following topics as they apply to your policy:

  1. Define the architecture for your system. Does it use client server, web, or application servers? Given the architecture, elaborate on what methods will be used in your database to support this architecture. Consider the following elements in the formulation of your policy:
    • Integration of DBMS security with client applications and operating systems
    • Integration of DBMS security with network operations
    • Integration of DBMS security with server operating systems
    • Integration of DBMS security with web servers and application servers
  2. Define requirements as they relate to database security. This includes, but is not limited to: connection pooling, proxies, application roles, file permissions, privileged accounts, password requirements, and other methods appropriate to your selection.

Part 3: User Accounts and Password Administration — 30 points

Address the following topics as they apply to your policy:

  1. User administration
  2. Password policies
  3. Profile definitions and assignments. What is the criterion for assignment of a profile to an account?

Part 4: Privileges and Roles — 30 points

Address the following topics as they apply to your policy.

  1. Security model selection
  2. Roles, including privileged roles assignment and administration and role policies
  3. System privileges
  4. Object privileges

Part 5: Database Security Operations — 30 points

Address the following topics as they apply to your policy

  1. Requirements and methodology for database logging
  2. Requirements and methodology for activity auditing

Part 6: Data Isolation Policies — 30 points

Address the following topics as they apply to your policy:

  1. Requirements for data isolation
  2. Database views
  3. Database triggers
  4. Database stored procedures

Part 7: Physical Environment for Secured Databases — 20 points

Address the following topics as they apply to your policy:

  1. Use of physical security and control mechanisms systems
  2. Database backup and restore practices relating to security

Part 8: Conclusion, Summary, and References — 20 points

  1. Develop a summary and conclusion for your paper
  2. Cite your references

About the Author

Follow me


{"email":"Email address invalid","url":"Website address invalid","required":"Required field missing"}