Database Security Controls Using CIS Benchmarks Training Course

5 days Database Systems Certificate on completion
Course codeSD-DS-043
Duration5 days
LevelFoundation to Intermediate
CategoryDatabase Systems
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Database security failures often arise from ordinary configuration decisions: shared administrator accounts, excessive server roles, unencrypted connections, exposed network listeners, weak audit retention, or default settings left unchanged after installation. These weaknesses are difficult to manage consistently across SQL Server, PostgreSQL, and other database estates, particularly when teams must demonstrate due diligence to auditors, customers, or internal risk committees. This course gives database and security professionals a repeatable CIS Benchmark-based method for identifying, prioritising, remediating, and evidencing database configuration risk.

Participants work through the structure and intent of CIS Benchmarks for database platforms, translating recommendations into operational controls rather than treating them as a compliance checklist. They learn to establish a secure baseline; interpret recommendation levels, profiles, rationales, and impact statements; collect configuration evidence; assess authentication, authorisation, encryption, logging, patching, and network exposure; and distinguish justified exceptions from unmanaged deviations. Practical examples cover Microsoft SQL Server and PostgreSQL, with techniques that transfer to other supported database technologies.

Instructor-led demonstrations are followed by guided configuration reviews, SQL-based evidence collection, CIS-CAT Pro Assessor exercises, remediation planning, and peer review of findings. Participants leave with a completed database CIS Benchmark assessment pack: a control applicability matrix, evidence register, prioritised remediation backlog, exception record, and implementation roadmap suitable for review by database owners, security teams, and auditors.

The course is suited to professionals who administer, secure, assess, or govern databases and need a defensible baseline method. It is equally valuable for managers seeking a practical way to standardise hardening work across environments without disrupting application availability or losing sight of operational constraints.

Course objectives

By the end of this course, participants will be able to:

  • Interpret CIS Benchmark recommendation levels, profiles, scoring logic, and implementation guidance for database platforms
  • Build a database security baseline from applicable CIS Benchmark controls and documented system scope
  • Collect configuration evidence using SQL queries, server settings, audit records, and CIS-CAT Pro Assessor results
  • Assess authentication, privileged access, password policy, and role assignment controls against CIS recommendations
  • Validate encryption, network exposure, logging, audit retention, and patch-management settings on database instances
  • Prioritise CIS Benchmark findings with a risk-based remediation backlog that records operational impact and ownership
  • Document compensating controls and formal exceptions in an auditable control applicability matrix
  • Produce a phased database hardening roadmap for implementation, retesting, and management reporting

Benefits of attending

For you

  • Gain a repeatable method for converting CIS Benchmark text into testable database security controls
  • Build credibility when advising application owners on hardening changes, operational impact, and accepted risk
  • Develop evidence-collection techniques that support database audits without relying on informal screenshots
  • Learn to write remediation and exception records that security governance teams can approve and track
  • Create a portfolio-ready CIS-aligned database assessment pack applicable to DBA, security engineering, and audit roles

For your organisation

  • Establish a consistent hardening baseline across database teams, environments, and deployment models
  • Reduce exposure from excessive privileges, insecure authentication, weak encryption, and incomplete auditing
  • Improve remediation decisions by linking each configuration finding to CIS rationale, risk, owner, and implementation impact
  • Produce reusable evidence registers and exception records that shorten audit and customer assurance activities
  • Create a phased remediation roadmap that reduces configuration risk without forcing unmanaged production changes

Target competencies

CIS control interpretationDatabase hardening assessmentConfiguration evidence collectionPrivileged access reviewRemediation prioritisationException documentation

Who should attend

  • Database Administrators — who must harden database instances while protecting application availability and performance
  • Database Security Engineers — who translate security requirements into repeatable technical database controls
  • Information Security Analysts — who assess configuration risk and require defensible evidence of control status
  • Infrastructure and Platform Engineers — who build and maintain database services across on-premises or cloud environments
  • IT Risk and Compliance Professionals — who need to test CIS-aligned controls and document justified exceptions
  • Technical Audit Professionals — who review database configuration evidence, remediation records, and control ownership

Requirements and prerequisites

Participants should understand basic relational database concepts, including instances, databases, schemas, users, roles, permissions, authentication, and SQL queries. Familiarity with administering either Microsoft SQL Server or PostgreSQL is strongly recommended, including the ability to connect to an instance and inspect configuration settings. Participants should also recognise core security concepts such as least privilege, encryption, logging, patching, and network segmentation. Experience with CIS Benchmarks, CIS-CAT Pro Assessor, formal auditing, or security certification is not required. Complete beginners can attend, but should expect to spend additional time becoming comfortable with database terminology and SQL-based evidence gathering.

Training methodology

The course combines focused instructor-led sessions with database configuration labs using Microsoft SQL Server and PostgreSQL examples. Participants inspect CIS Benchmark recommendations, run structured evidence checks, compare observed settings with required baselines, and record findings in assessment templates. Small-group case work addresses realistic constraints such as legacy applications, shared service accounts, and audit-log storage limits. Each day closes with a practical output that feeds the final assessment pack. On day five, participants present a prioritised remediation roadmap and receive instructor feedback on evidence quality, exception handling, and implementation sequencing.

Course outline

Day 1: CIS Benchmark foundations for database security

  • Database attack surfaces and configuration-driven risk
  • CIS Benchmark structure, recommendation identifiers, and profile selection
  • Level 1 and Level 2 control intent and implementation trade-offs
  • Control applicability across production, development, test, and managed database environments
  • Secure baseline concepts for database instances and supporting services
  • Asset scope definition and database configuration inventory creation
  • Control applicability matrices and evidence-register design

Workshop: Participants define the scope of a sample database estate and produce a control applicability matrix identifying applicable, non-applicable, and review-required CIS recommendations.

Day 2: Identity, privilege, and access controls

  • Database authentication modes and identity-source selection
  • Default accounts, shared accounts, and service-account risk
  • Password policy, credential rotation, and account-lockout configuration
  • Server roles, database roles, schemas, and least-privilege design
  • Privileged access review using system catalog queries
  • Segregation of duties for DBA, application, and security administration
  • CIS-aligned access-control evidence and compensating-control records

Workshop: Participants review a SQL Server and PostgreSQL access model, identify excessive privileges, and produce a role-remediation and evidence-collection worksheet.

Day 3: Network, encryption, and platform hardening

  • Database listener exposure, ports, and network segmentation controls
  • TLS configuration and encrypted client-to-server connections
  • Certificate management and encryption protocol validation
  • Encryption at rest, key protection, and backup encryption considerations
  • Secure configuration of database features, extensions, and external access
  • Patch levels, version support status, and vulnerability remediation dependencies
  • Manual CIS Benchmark verification using configuration settings and SQL queries

Workshop: Participants assess a deliberately misconfigured database instance and produce a prioritised hardening backlog covering network, TLS, encryption, and platform settings.

Day 4: Logging, monitoring, and automated assessment

  • Database audit policy design and CIS logging recommendations
  • Capturing authentication, privilege-change, and data-access events
  • Audit destination protection, retention periods, and storage-capacity planning
  • Log review responsibilities and escalation criteria
  • CIS-CAT Pro Assessor workflow and benchmark assessment outputs
  • Validating automated findings against live configuration evidence
  • False positives, environmental constraints, and retest procedures

Workshop: Participants run and interpret a CIS-CAT Pro Assessor-based assessment scenario, validate selected findings manually, and complete an evidence register.

Day 5: Remediation governance and assessment reporting

  • Risk-based finding prioritisation using exploitability, exposure, and business criticality
  • Remediation sequencing for production databases and change-control windows
  • Implementation testing, rollback planning, and post-change validation
  • Compensating controls and time-bound exception management
  • Metrics for baseline compliance, overdue remediation, and repeat findings
  • Management reporting for database owners, security leaders, and auditors
  • CIS Benchmark assessment-pack assembly and continuous review cycles

Workshop: Participants assemble and present a complete CIS-aligned database assessment pack containing findings, evidence, exceptions, remediation owners, and a 90-day implementation roadmap.

Tools & standards covered

CIS Benchmarks, CIS-CAT Pro Assessor, Microsoft SQL Server, PostgreSQL

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand database users, roles, permissions, basic SQL, and common instance configuration concepts. Deep expertise in every database platform is not required, but participants gain more from the labs if they have administered or supported SQL Server, PostgreSQL, or a comparable platform.

Practical examples focus on Microsoft SQL Server and PostgreSQL because they provide clear, transferable examples of CIS-aligned database controls. The assessment, evidence, exception, and remediation methods can be applied to other database technologies where a relevant CIS Benchmark is available.

For live online delivery, a laptop capable of running a modern web browser and connecting to the training lab is required. Training environments and exercise materials are provided; participants do not need to install production database software or hold a CIS-CAT Pro Assessor licence.

This course is organised around using CIS Benchmarks as an assessment and implementation method, not around general query tuning or database design. It concentrates on translating benchmark recommendations into evidence, risk decisions, remediation actions, and auditable exception records.

You can use the control applicability matrix, evidence register, and remediation backlog as templates for an initial database baseline review. The method supports both one-off assessment projects and recurring control assurance cycles following platform upgrades, migrations, or audit findings.

You leave with a completed database CIS Benchmark assessment pack developed through the course exercises. It includes a scoped control matrix, collected evidence, prioritised findings, documented exceptions, and a phased remediation roadmap that can be adapted to your own estate.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Database Systems

5 Days Certificate

Apache Cassandra Data Modelling and Operations Training Course

Apache Cassandra is often selected for high availability and multi-region scale, then undermined by relational data models, oversized partit…

5 Days Certificate

Advanced Database Performance Tuning and Architecture Training Course

Database latency, lock contention, CPU saturation and uncontrolled storage growth rarely have a single cause. Senior engineers need to disti…

5 Days Certificate

MongoDB Database Development and Operations Training Course

MongoDB teams need more than the ability to write a find() query. Developers and operations staff must model changing data without creating …

10 Days Certificate

Database Systems for Data Engineers Training Course

Data engineers are expected to make data reliable, available and economical to use, yet many pipelines fail because the underlying database …