Selecting a secure database
Apr 21st, 2007 by Jesper Kråkhede
When looking at the requirements for PCI DSS it is quite obvious that you need a more or less hack proof setup. This is all good and well but during the latest years changes has been done in how a hacker works. Now it is not only the operating system that is attacked but the database engine also. Therefor you should read about exploits on the database engines also before making a selection. You could choose an insecure database but make very well sure that you have compensating controls in place. And remember, a firewall that allows traffic to the database is NOT a compensating control.