Security Issues
• Database security is a broad area that addresses many issues,
including the following:
– Various legal and ethical issues regarding the right to access certain
information
• for example, some information may be deemed to be private and cannot be
accessed legally by unauthorized organizations or persons. In the United States,
there are numerous laws governing privacy of information.
– Policy issues at the governmental, institutional, or corporate level as to
what kinds of information should not be made publicly available
• for example, credit ratings and personal medical records.
– System-related issues such as the system levels at which various
security functions should be enforced
• for example, whether a security function should be handled at the physical
hardware level, the operating system level, or the DBMS level.
– The need in some organizations to identify multiple security levels and to
categorize the data and users based on these classifications
• for example, top secret, secret, confidential, and unclassified. The security policy
of the organization with respect to permitting access to various classifications of
data must be enforced.