You are the new DBA for the XYZ company, you have been asked to research best practices for security policies and procedures. Specifically, what information can you provide regarding controls related to each of the following?

  • Personnel 
  • Physical access 
  • Maintenance 
  • Data privacy

Provide examples of each type of control.

You have also been asked to write a draft policy and procedure handbook that details the possible areas of data security threats for XYZ company. Specifically, the company would like to be able to understand the mitigation of risks related to each of the following:

  • Accidental loss
  • Theft and fraud
  • Loss of privacy or confidentiality
  • Loss of data integrity
  • Loss of availability

