Site Sections => About Us | Consultancy | Training | Software | Publications | Open Source | Support | Open Standards | FAQ | Jobs
Site Style Info

Microsoft Course 2787 - Designing Security for Microsoft SQL Server 2005 — A 2-Day Course

Course Synopsis

This two-day instructor-led course enables database administrators who work with enterprise environments to design security for database systems using Microsoft SQL ServerT 2005. The course emphasizes that students should think about the whole environment, which includes business needs, regulatory requirements, network systems, and database considerations during design. Students will also learn how to monitor security and respond to threats.

Intended Audience

This course is intended for current professional database administrators who have three or more years of on-the-job experience administering SQL Server database solutions in an enterprise environment.

Course Prerequisites

Before attending this course, students should have the following prerequisites:

  • Have basic knowledge of security protocols and how they work. For example, Windows NT LAN Manager (NTLM) or Kerberos
  • Have basic knowledge of public key infrastructure (PKI) systems. For example, how public and private keys work, strengths and weaknesses, and what they are used for
  • Have working knowledge of network architectures and technologies. For example, how a firewall works, how IPSec works in a networking context, and common vulnerability points
  • Have working knowledge of Active Directory directory service. For example, security models, policies, group policy objects (GPOs), and organizational units (OUs)
  • Be able to design a database to third normal form (3NF) and know the tradeoffs when backing out of the fully normalized design (denormalization) and designing for performance and business requirements in addition to being familiar with design models, such as Star and Snowflake schemas
  • Have strong monitoring and troubleshooting skills
  • Have experience creating Microsoft Office Visio drawings or have equivalent knowledge
  • Have strong knowledge of the operating system and platform. That is, how the operating system integrates with the database, what the platform or operating system can do, interaction between the operating system and the database
  • Have basic knowledge of application architecture. That is, different methods of implementing security in an application, how applications can be designed in three layers, what applications can do, the interaction between applications and the database, and interactions between the database and the platform or operating system
  • Have knowledge about network security tools. For example, sniffer and port scanning. Must understand how they should be used
  • Be able to use patch management systems
  • Have knowledge of common attack methods. For example, buffer overflow, and replay attacks
  • Be familiar with SQL Server 2005 features, tools, and technologies
  • Have a Microsoft Certified Technology Specialist: Microsoft SQL Server 2005 credential or equivalent experience
  • In addition, it is recommended, but not required, that students have completed:
    • Course 2778: Writing Queries Using Microsoft SQL Server 2005 Transact-SQL
    • Course 2779: Implementing a Microsoft SQL Server 2005 Database
    • Course 2780: Maintaining a Microsoft SQL Server 2005 Database

Publicly scheduled dates, locations, and prices

Central London — £395 (+VAT)

  • 29–30 May 2008
  • 9–10 Jul 2008
  • 29–30 Jul 2008
  • 1–2 Sep 2008
  • 22–23 Sep 2008
  • 27–28 Oct 2008
  • 3–4 Nov 2008
  • 7–8 Jan 2009
  • 12–13 Jan 2009
  • 6–7 Apr 2009
  • 22–23 Jun 2009

Leeds — £395 (+VAT)

  • 11–12 Aug 2008
  • 22–23 Sep 2008
  • 17–18 Nov 2008

Manchester — £395 (+VAT)

  • 25–26 Jun 2008

Wokingham — £395 (+VAT)

  • 28–29 Jul 2008
  • 24–25 Nov 2008

Sunderland — £395 (+VAT)

  • 4–5 Aug 2008
  • 20–21 Oct 2008

Coventry — £395 (+VAT)

  • 15–16 Dec 2008

Outline Course Contents

Introduction to Designing SQL Server Security

This module introduces the principles and methodology of designing SQL Server security. This module also explains the benefits of having a security policy in place and the process of creating a security policy. In addition, this module teaches you the importance of monitoring the security of SQL Server.

  • Principles of Database Security
  • Methodology for Designing a SQL Server Security Policy
  • Monitoring SQL Server Security

Designing a SQL Server Systems Infrastructure Security Policy

This module provides the guidelines for implementing server-level security using authentication methods. This module also provides the knowledge required to develop a Microsoft Windows server-level security policy. To enable you to do this, this module provides the guidelines to create password policy and determine service accounts permissions. In addition, this module explains how to select an appropriate encryption method to develop a secure communication policy. This module also explains the monitoring standards for SQL Server.

  • Integrating with Enterprise Authentication Systems
  • Developing Windows Server-Level Security Policies
  • Developing a Secure Communication Policy
  • Defining SQL Server Security Monitoring Standards

Designing Security Policies for Instances and Databases

This module explains how to design SQL Server instance-level, database-level, and object-level security policies. This module teaches the security monitoring standards for instances and databases.

  • Designing an Instance-Level Security Policy
  • Designing a Database-Level Security Policy
  • Designing an Object-Level Security Policy
  • Defining Security Monitoring Standards for Instances and Databases

Integrating Data Encryption into a Database Security Design

This module provides the guidelines and considerations for security data using encryption and certificates. This module also describes various data encryption policies. Finally, this module shows how to determine a key storage method.

  • Securing Data by Using Encryption and Certificates
  • Designing Data Encryption Policies
  • Determining a Key Storage Method

Designing a Security Exceptions Policy

This module provides guidelines for gathering business and regulatory requirements and comparing them with existing policy. This module also covers how to determine the exceptions and their impact on security.

  • Analyzing Business and Regulatory Requirements
  • Determining the Exceptions and their Impact

Designing a Response Strategy for Threats and Attacks

This module provides guidelines to respond to virus and worm attacks, denial-of-service attacks, and injection attacks.

  • Designing a Response Policy for Virus and Worm Attacks
  • Designing a Response Policy for Denial-of-Service Attacks
  • Designing a Response Policy for Internal and SQL Injection Attacks

SQL Server training UK enquiries

UK Training enquiries and feedback form.

SQL Server training UK prices

For publicly scheduled training (individual places), see our UK training schedule.

In-house training for company groups is charged at a daily rate per group — see our In-House UK Training Guidelines.

Publicly Scheduled Training Locations

We currently run public training courses in the following locations:

  • London, UK
  • Leeds, West Yorkshire, UK
  • Birmingham, West Midlands, UK
  • Carshalton, Surrey, UK
  • Chester, North West, UK
  • Coventry, West Midlands, UK
  • Edinburgh, Scotland, UK
  • Glasgow, Scotland, UK
  • Harwell, Oxfordshire, UK
  • Manchester, North West, UK
  • Milton Keynes, Buckinghamshire, UK
  • Newark, Nottinghamshire, UK
  • Reading, Berkshire, UK
  • Slough, Berkshire, UK
  • Stevenage, Hertfordshire, UK
  • Wakefield, West Yorkshire, UK
  • Wokingham, Berkshire, UK

Most UK public training courses are available on a monthly basis.

Please see the individual course outlines or our public training schedule for details.

In-house (on-site) training locations

We deliver in-house courses at client premises and/or training facilities in any part of the world which is practically and commercially accessible.

Our In-house training guidelines outline our basic requirements and our UK pricing structure. To estimate costs for training in other countries, simply convert to your local currency and then make a rough calculation of our tutor's costs for travelling to and staying at your location.


West Yorkshire Office

GBdirect Ltd
Training Division
Bradford Design Exchange
34 Peckover Street
BRADFORD
BD1 5BD
West Yorkshire
United Kingdom

training@gbdirect.co.uk

Training: 0800 651 0338
General: +44 (0)870 200 7273
Finance: +44 (0)1353 615 174

Please call between 0900 and 1700 (UK time) on Monday to Friday


South East Regional Office

GBdirect Ltd
Training Division
18 Lynn Rd
ELY
CB6 1DA
Cambridgeshire
United Kingdom

training@gbdirect.co.uk

Training: 0800 651 0338
General: +44 (0)870 200 7273
Finance: +44 (0)1353 615 174

Please call between 0900 and 1700 (UK time) on Monday to Friday


Please note:
Non-training enquiries should be directed, initially, to our UK national office in Bradford (West Yorkshire), even if the enquiry concerns services delivered in London or South/East England. Clients in London and the South East will typically be handled by staff working in the London or Cambridge areas.