Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Other Discussions
  3. Article Writing
  4. MS SQL Server & IIS Security... military grade?

MS SQL Server & IIS Security... military grade?

Scheduled Pinned Locked Moved Article Writing
questiondatabasesql-serversysadminwindows-admin
2 Posts 2 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A Offline
    A Offline
    Andrew Connell
    wrote on last edited by
    #1

    I have a developer background, but in a new job, I fell into the role of security expert for Microsoft's SQL Server (v7 & 2000) and IIS (v4 & 5). I am contracted to a US Dept. of Defense agency. When they were doing a big security push, they didn't have any IIS or SQL Server "experts/gurus." I'm no self-proclaimed expert, but because I was familiar with both thanks to my MCDBA cert, I was tasks with locking them down. In the last few months, I've learned quite a bit about security on these to systems. The military bases their security off the specifications created by a group of software companies & govt agencies such as Microsoft, Sun, IBM, HP, CIA, and the NSA. There's a gold & platinum standard. These standards are used by many of the people in the private sector... the military uses the platinum standard. What is thethe point of this posting? I was thinking about writing a few articles based on this security. Would this be something of interest to others? -AC

    P 1 Reply Last reply
    0
    • A Andrew Connell

      I have a developer background, but in a new job, I fell into the role of security expert for Microsoft's SQL Server (v7 & 2000) and IIS (v4 & 5). I am contracted to a US Dept. of Defense agency. When they were doing a big security push, they didn't have any IIS or SQL Server "experts/gurus." I'm no self-proclaimed expert, but because I was familiar with both thanks to my MCDBA cert, I was tasks with locking them down. In the last few months, I've learned quite a bit about security on these to systems. The military bases their security off the specifications created by a group of software companies & govt agencies such as Microsoft, Sun, IBM, HP, CIA, and the NSA. There's a gold & platinum standard. These standards are used by many of the people in the private sector... the military uses the platinum standard. What is thethe point of this posting? I was thinking about writing a few articles based on this security. Would this be something of interest to others? -AC

      P Offline
      P Offline
      Paul Watson
      wrote on last edited by
      #2

      Andrew Connell wrote: Would this be something of interest to others? Hell yes! :-D We can either just carry on moaning about IIS security or we can learn how to lock it down as is needed. A systematic article on locking down IIS and SQL would be very useful, especially if it comes from real world experience and not just theoretical pondering :)

      Paul Watson
      Bluegrass
      Cape Town, South Africa

      Ray Cassick wrote:
      Well I am not female, not gay and I am not Paul Watson

      1 Reply Last reply
      0
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Don't have an account? Register

      • Login or register to search.
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups