Skip to content

Latest commit

 

History

History
51 lines (39 loc) · 2.07 KB

File metadata and controls

51 lines (39 loc) · 2.07 KB
title Database Encryption | SEAL
description Encrypt databases at rest and in use: TDE, column-level crypto, keys held outside the DB host, and performance trade-offs for protocol backends.
tags
Engineer/Developer
Security Specialist
contributors
role users
wrote
role users
reviewed
role users
fact-checked

import { TagList, AttributionList, ContributeFooter } from '../../../components'

Database Encryption

🔑 Key Takeaway: Databases that hold PII or secrets need encryption of files/backups and sensitive columns, plus key management and access control — TDE alone is not a complete design.

Databases often concentrate regulated and high-value data. Encryption reduces the impact of storage theft and some classes of backup leakage, but application and access control still matter.

Often, databases contain information that should not be publicly available. In order to protect your database, you may consider implementing the following best practices:

Best practices

  1. Use strong encryption algorithms to encrypt database files and backups.
  2. Encrypt sensitive columns within the database, such as those containing personally identifiable information (PII).
  3. Use Transparent Data Encryption (TDE) to automatically encrypt and decrypt data stored in the database.
  4. Implement robust key management practices, including the use of HSMs and regular key rotation depending on your use case.
  5. Enforce strict access controls to prevent unauthorized access to encrypted data.

Further reading