Protecting what is held.
WHAT COUNTS AS SENSITIVE
Personal details Financial information Health information Credentials Anything a regulation names
WHAT TO COLLECT
The minimum needed.
WHY
What is not held cannot be breached.
WHAT TO NEVER STORE
Passwords in recoverable form Full payment card numbers, unless you are equipped for that obligation Security codes from cards, ever
WHAT TO STORE FOR PASSWORDS
A hash from a function designed for passwords.
WHY NOT A GENERAL HASH
They are fast, which is exactly wrong for this purpose.
WHAT ENCRYPTION AT REST PROTECTS
Data on stolen disks or backups.
WHAT IT DOES NOT PROTECT
Anything reachable through the running database.
WHY THAT MATTERS
It is frequently oversold as a general defence.
WHAT COLUMN-LEVEL ENCRYPTION PROVIDES
Protection even from someone reading the table.
WHAT IT COSTS
Inability to index or search the column meaningfully.
WHAT TO ENCRYPT
Connections, always Backups, always
WHAT TO RESTRICT
Which accounts can read sensitive tables.
WHAT TO LOG
Access to them.
WHAT TO PLAN
Deletion, when retention expires.
WHAT TO TAKE ADVICE ON
Your obligations under applicable data protection law.