Database Security Controls Using CIS Benchmarks Training Course
| Course code | SD-DS-043 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Database Systems |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Database security failures often arise from ordinary configuration decisions: shared administrator accounts, excessive server roles, unencrypted connections, exposed network listeners, weak audit retention, or default settings left unchanged after installation. These weaknesses are difficult to manage consistently across SQL Server, PostgreSQL, and other database estates, particularly when teams must demonstrate due diligence to auditors, customers, or internal risk committees. This course gives database and security professionals a repeatable CIS Benchmark-based method for identifying, prioritising, remediating, and evidencing database configuration risk.
Participants work through the structure and intent of CIS Benchmarks for database platforms, translating recommendations into operational controls rather than treating them as a compliance checklist. They learn to establish a secure baseline; interpret recommendation levels, profiles, rationales, and impact statements; collect configuration evidence; assess authentication, authorisation, encryption, logging, patching, and network exposure; and distinguish justified exceptions from unmanaged deviations. Practical examples cover Microsoft SQL Server and PostgreSQL, with techniques that transfer to other supported database technologies.
Instructor-led demonstrations are followed by guided configuration reviews, SQL-based evidence collection, CIS-CAT Pro Assessor exercises, remediation planning, and peer review of findings. Participants leave with a completed database CIS Benchmark assessment pack: a control applicability matrix, evidence register, prioritised remediation backlog, exception record, and implementation roadmap suitable for review by database owners, security teams, and auditors.
The course is suited to professionals who administer, secure, assess, or govern databases and need a defensible baseline method. It is equally valuable for managers seeking a practical way to standardise hardening work across environments without disrupting application availability or losing sight of operational constraints.
Course objectives
By the end of this course, participants will be able to:
- Interpret CIS Benchmark recommendation levels, profiles, scoring logic, and implementation guidance for database platforms
- Build a database security baseline from applicable CIS Benchmark controls and documented system scope
- Collect configuration evidence using SQL queries, server settings, audit records, and CIS-CAT Pro Assessor results
- Assess authentication, privileged access, password policy, and role assignment controls against CIS recommendations
- Validate encryption, network exposure, logging, audit retention, and patch-management settings on database instances
- Prioritise CIS Benchmark findings with a risk-based remediation backlog that records operational impact and ownership
- Document compensating controls and formal exceptions in an auditable control applicability matrix
- Produce a phased database hardening roadmap for implementation, retesting, and management reporting
Benefits of attending
For you
- Gain a repeatable method for converting CIS Benchmark text into testable database security controls
- Build credibility when advising application owners on hardening changes, operational impact, and accepted risk
- Develop evidence-collection techniques that support database audits without relying on informal screenshots
- Learn to write remediation and exception records that security governance teams can approve and track
- Create a portfolio-ready CIS-aligned database assessment pack applicable to DBA, security engineering, and audit roles
For your organisation
- Establish a consistent hardening baseline across database teams, environments, and deployment models
- Reduce exposure from excessive privileges, insecure authentication, weak encryption, and incomplete auditing
- Improve remediation decisions by linking each configuration finding to CIS rationale, risk, owner, and implementation impact
- Produce reusable evidence registers and exception records that shorten audit and customer assurance activities
- Create a phased remediation roadmap that reduces configuration risk without forcing unmanaged production changes
Target competencies
Who should attend
- Database Administrators — who must harden database instances while protecting application availability and performance
- Database Security Engineers — who translate security requirements into repeatable technical database controls
- Information Security Analysts — who assess configuration risk and require defensible evidence of control status
- Infrastructure and Platform Engineers — who build and maintain database services across on-premises or cloud environments
- IT Risk and Compliance Professionals — who need to test CIS-aligned controls and document justified exceptions
- Technical Audit Professionals — who review database configuration evidence, remediation records, and control ownership
Requirements and prerequisites
Participants should understand basic relational database concepts, including instances, databases, schemas, users, roles, permissions, authentication, and SQL queries. Familiarity with administering either Microsoft SQL Server or PostgreSQL is strongly recommended, including the ability to connect to an instance and inspect configuration settings. Participants should also recognise core security concepts such as least privilege, encryption, logging, patching, and network segmentation. Experience with CIS Benchmarks, CIS-CAT Pro Assessor, formal auditing, or security certification is not required. Complete beginners can attend, but should expect to spend additional time becoming comfortable with database terminology and SQL-based evidence gathering.
Training methodology
The course combines focused instructor-led sessions with database configuration labs using Microsoft SQL Server and PostgreSQL examples. Participants inspect CIS Benchmark recommendations, run structured evidence checks, compare observed settings with required baselines, and record findings in assessment templates. Small-group case work addresses realistic constraints such as legacy applications, shared service accounts, and audit-log storage limits. Each day closes with a practical output that feeds the final assessment pack. On day five, participants present a prioritised remediation roadmap and receive instructor feedback on evidence quality, exception handling, and implementation sequencing.
Course outline
Day 1: CIS Benchmark foundations for database security
- Database attack surfaces and configuration-driven risk
- CIS Benchmark structure, recommendation identifiers, and profile selection
- Level 1 and Level 2 control intent and implementation trade-offs
- Control applicability across production, development, test, and managed database environments
- Secure baseline concepts for database instances and supporting services
- Asset scope definition and database configuration inventory creation
- Control applicability matrices and evidence-register design
Workshop: Participants define the scope of a sample database estate and produce a control applicability matrix identifying applicable, non-applicable, and review-required CIS recommendations.
Day 2: Identity, privilege, and access controls
- Database authentication modes and identity-source selection
- Default accounts, shared accounts, and service-account risk
- Password policy, credential rotation, and account-lockout configuration
- Server roles, database roles, schemas, and least-privilege design
- Privileged access review using system catalog queries
- Segregation of duties for DBA, application, and security administration
- CIS-aligned access-control evidence and compensating-control records
Workshop: Participants review a SQL Server and PostgreSQL access model, identify excessive privileges, and produce a role-remediation and evidence-collection worksheet.
Day 3: Network, encryption, and platform hardening
- Database listener exposure, ports, and network segmentation controls
- TLS configuration and encrypted client-to-server connections
- Certificate management and encryption protocol validation
- Encryption at rest, key protection, and backup encryption considerations
- Secure configuration of database features, extensions, and external access
- Patch levels, version support status, and vulnerability remediation dependencies
- Manual CIS Benchmark verification using configuration settings and SQL queries
Workshop: Participants assess a deliberately misconfigured database instance and produce a prioritised hardening backlog covering network, TLS, encryption, and platform settings.
Day 4: Logging, monitoring, and automated assessment
- Database audit policy design and CIS logging recommendations
- Capturing authentication, privilege-change, and data-access events
- Audit destination protection, retention periods, and storage-capacity planning
- Log review responsibilities and escalation criteria
- CIS-CAT Pro Assessor workflow and benchmark assessment outputs
- Validating automated findings against live configuration evidence
- False positives, environmental constraints, and retest procedures
Workshop: Participants run and interpret a CIS-CAT Pro Assessor-based assessment scenario, validate selected findings manually, and complete an evidence register.
Day 5: Remediation governance and assessment reporting
- Risk-based finding prioritisation using exploitability, exposure, and business criticality
- Remediation sequencing for production databases and change-control windows
- Implementation testing, rollback planning, and post-change validation
- Compensating controls and time-bound exception management
- Metrics for baseline compliance, overdue remediation, and repeat findings
- Management reporting for database owners, security leaders, and auditors
- CIS Benchmark assessment-pack assembly and continuous review cycles
Workshop: Participants assemble and present a complete CIS-aligned database assessment pack containing findings, evidence, exceptions, remediation owners, and a 90-day implementation roadmap.
Tools & standards covered
CIS Benchmarks, CIS-CAT Pro Assessor, Microsoft SQL Server, PostgreSQL
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Database Systems
Apache Cassandra Data Modelling and Operations Training Course
Apache Cassandra is often selected for high availability and multi-region scale, then undermined by relational data models, oversized partit…
Advanced Database Performance Tuning and Architecture Training Course
Database latency, lock contention, CPU saturation and uncontrolled storage growth rarely have a single cause. Senior engineers need to disti…
MongoDB Database Development and Operations Training Course
MongoDB teams need more than the ability to write a find() query. Developers and operations staff must model changing data without creating …
Database Systems for Data Engineers Training Course
Data engineers are expected to make data reliable, available and economical to use, yet many pipelines fail because the underlying database …