Implementing database security: using attack analysis to improve your defences
Josh Shaul · Network Security · 2008
Following a comprehensive infrastructure assessment, the organisation should carry out in sequence the process outlined below. In this pre-mitigation phase, the organisation will identify risk by running discovery scans to locate all databases, and vulnerability scans to identify and prioritise existing vulnerabilities. A prioritised list will help the organisation decide where to start and to document a security improvement plan. The plan aids with systematically securing databases and it will also demonstrate steady progress against goals.