Download presentation
Presentation is loading. Please wait.
Published byJessica Marybeth Hubbard Modified over 9 years ago
1
IT Pro Day Auditing in SQL Server 2012 Charley Hanania Principal Consultant, QS2 AG – Quality Software Solutions www.qs2.ch
2
Now: Database Consultant at QS2 AG Formerly: Production Product Owner of MS SQL Server Platform at UBS Investment Bank IT Professional since 1992 SQL Server Certified since 1988 On SQL Server since 1995 Version 4 on OS/2 Community Microsoft MVP: SQL ServerSQL Server PASS Chapter Leader – Switzerland PASS Regional Mentor – Europe European PASS Conference Lead International Event Speaker MCT Regional Lead (Switzerland) Database Days Conference Switzerland Lead B.Sc (Computing), MCP, MCDBA, MCITP, MCTS, MCT, Microsoft MVP: SQL Server, MCT Regional Lead (Switzerland)
3
Agenda Chapter 2/4
4
Agenda
5
Overview of regulatory standards and compliance
6
The Compliance and Policy Ecosystem Why all this is so important…
7
1. Identify Issues and Risks 2. Develop Policies to mitigate them 3. Architect Procedures & Solutions (frameworks) to meet (comply with) Policies 4. Implement methods to report compliance levels 5. Implement methods & countermeasures for exceptions and comprised systems 6. Implement Process Improvement methodologies for framework maturity
8
Major frameworks used for establishing IT controls…
9
AICPA/CICA Trust Services, Principles, and Criteria Carnegie Mellon University Software Engineering Institute (CMU/SEI) OCTAVE CICA CoCo – Criteria of Control Framework CICA IT Control Guidelines CMMI – Capability Maturity Model Integration CobiT – Control Objectives for Information and related Technology COSO – Internal Control Integrated Framework GAISP – Generally Accepted Information Security Principles ISF Standard of Good Practice for Information Security ISO 17799:2005 ISO 9000 ITIL – the IT Infrastructure Library Malcolm Baldridge National Quality Program Organization for Economic Cooperation and Development (OECD) Principles of Corporate Governance OPMMM – Organizational Project Management Maturity Model Six Sigma OECD - Organization for Economic Cooperation and Development Guidelines on the Protection of Privacy and Transborder Flows of Personal Data NIST SP 800-53 - Recommended Security Controls for Federal Information Systems The FFIEC Information Technology Examination Handbook series The major players in the IT framework arena are: source: www.unifiedcompliance.com Note: There is no single framework that is all encompassing and "complete" Some frameworks focus on process maturity analysis and others focus more on standardised policies and checklists. These frameworks are used to bring organisations closer to compliance with one or more regulatory standards
10
Relevant Technology Components within SQL Server
12
SQL Server Audit Framework
13
Feature Overview SQL Server Audit Framework
14
SQL Server Audit
16
Enhancements in SQL Server 2012 SQL Server Audit Framework
18
Demo SQL Server Audit Framework
19
Policy Based Mgt Framework
20
Feature Overview Policy Based Mgt Framework
21
A framework which exposes sql server's properties as facets, allows you to create conditions which report back the status of those facets, and then create policies around those conditions. You can just report on those or enforce them. You can also import and export them and apply them to multiple servers. Policy Based Management
23
Demo Policy Based Mgt Framework
24
Wrap-Up
25
Summary Wrap-Up
26
The Audit Feature is enhanced in SQL Server 2012 It is a tool in the “Security and Compliance” arsenal It needs to be architected into the overall operational strategy, alongside strategic tools, policies and processes.
27
REGISTER NOW AND GET 10% OFF DISCOUNT CODE: CHMTD12 (Valid until December 10, 2012) A Preconference Day with 5-7 parallel technical workshops, focussed on critical role-based skills for Data Professionals. Two days of conference seminars across 3 technical tracks: - Database Administration - Business Intelligence - Data Platform Application Development. Check out www.databasedays.comwww.databasedays.com
28
Questions? Wrap-Up
29
Contact Info Wrap-Up
30
Email: Charley.Hanania@sqlpass.orgCharley.Hanania@sqlpass.org Website: http://www.sqlpass.chhttp://www.sqlpass.ch Twitter: http://www.twitter.com/CharleyHananiahttp://www.twitter.com/CharleyHanania Blog: http://blogs.mssqltips.com/blogs/charleyhananiahttp://blogs.mssqltips.com/blogs/charleyhanania Linked-in: http://www.linkedin.com/in/charleyhananiahttp://www.linkedin.com/in/charleyhanania Database Days: http://www.databasedays.comhttp://www.databasedays.com
Similar presentations
© 2025 SlidePlayer.com Inc.
All rights reserved.