2 cissp ® Official Study Guide Eighth Edition


Open Database Connectivity



Download 19,3 Mb.
Pdf ko'rish
bet839/881
Sana08.04.2023
Hajmi19,3 Mb.
#925879
1   ...   835   836   837   838   839   840   841   842   ...   881
Bog'liq
(CISSP) Mike Chapple, James Michael Stewart, Darril Gibson - CISSP Official Study Guide-Sybex (2018)

Open Database Connectivity
Open Database Connectivity (ODBC) is a database feature that allows applications to com-
municate with different types of databases without having to be directly programmed for 
interaction with each type. ODBC acts as a proxy between applications and backend data-
base drivers, giving application programmers greater freedom in creating solutions without 
having to worry about the backend database system. Figure 20.9 illustrates the relationship 
between ODBC and a backend database system.


904
Chapter 20 

Software Development Security
F I g u r e 2 0 . 9
ODBC as the interface between applications and a backend database 
system
O
D
B
C
Application
ODBC
Manager
Database
Drivers
Database
Types
NoSQL
As database technology evolves, many organizations are turning away from the relational 
model for cases where they require increased speed or their data does not neatly fit into 
tabular form. NoSQL databases are a class of databases that use models other than the 
relational model to store data.
These are the three major classes of NoSQL database:

Key/value stores
are perhaps the simplest possible form of database. They store infor-
mation in key/value pairs, where the key is essentially an index used to uniquely iden-
tify a record, which consists of a data value. Key/value stores are useful for high-speed 
applications and very large datasets.

Graph databases
store data in graph format, using nodes to represent objects and edges 
to represent relationships. They are useful for representing any type of network, such 
as social networks, geographic locations, and other datasets that lend themselves to 
graph representations.

Document stores
are similar to key/value stores in that they store information using 
keys, but the type of information they store is typically more complex than that in a 
key/value store and is in the form of a document. Common document types used in 
document stores include Extensible Markup Language (XML) and JavaSsript Object 
Notation (JSON).
The security models used by NoSQL databases may differ significantly from relational 
databases. Security professionals in organizations that use this technology should familiar-
ize themselves with the security features of the solutions they use and consult with database 
teams in the design of appropriate security controls.
Storing Data and Information
Database management systems have helped harness the power of data and gain some modi-
cum of control over who can access it and the actions they can perform on it. However, 
security professionals must keep in mind that DBMS security covers access to information 


Storing Data and Information 
905
through only the traditional “front-door” channels. Data is also processed through a com-
puter’s storage resources—both memory and physical media. Precautions must be in place 
to ensure that these basic resources are protected against security vulnerabilities as well. 
After all, you would never incur a lot of time and expense to secure the front door of your 
home and then leave the back door wide open, would you?

Download 19,3 Mb.

Do'stlaringiz bilan baham:
1   ...   835   836   837   838   839   840   841   842   ...   881




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish