Reducing exposure.
WHAT TO DO FIRST
Establish whether it needs to accept connections from outside at all.
WHAT THE ANSWER USUALLY IS
No.
WHAT TO DO THEN
Bind it to the local address.
WHY THAT ALONE PREVENTS MOST ATTACKS
Exposed databases are scanned and attacked continuously.
WHAT TO DO IF REMOTE ACCESS IS NEEDED
Restrict by source address at the firewall Require encrypted connections Never expose it to the whole internet
WHAT TO ENFORCE ON ACCOUNTS
Strong, unique passwords Host restrictions Minimum privileges No wildcards
WHAT TO REMOVE
Default and anonymous accounts Test databases Accounts nobody can identify
WHAT TO ENCRYPT
Connections, always Data at rest, where the data warrants it Backups
WHY BACKUPS SPECIFICALLY
They are frequently the least protected copy of everything.
WHAT TO AUDIT
Who connects, from where Privilege changes Failed authentication
WHAT TO KEEP UPDATED
The database software.
WHY
Vulnerabilities are published and exploited quickly.
WHAT TO NEVER PUT IN THE DATABASE
Passwords stored recoverably Payment card numbers
WHAT TO CHECK ON ANY SERVER YOU INHERIT
What is listening, and on which address.