Database security checklist

This list summarizes features, recommendations, and best practices for implementing HCD security features on your clusters and databases. For more information about the HCD security architecture, see HCD security overview.

Authentication and authorization
  • Enable authentication on all nodes:

    • Internal: Username/password pairs stored in the internal database. Use strong passwords for internal authentication.

    • LDAP: External LDAP service integration, such as Active Directory or OpenLDAP.

    • OpenID Connect (OIDC): Modern identity providers for enterprise SSO.

    HCD authentication is only supported for database connections.

  • Configure RBAC:

    • Create admin roles and users.

    • Create specific roles for different user types.

    • Grant minimum necessary permissions.

  • Create a non-default superuser role, and then disable the default cassandra role.

  • Regularly review and update role assignments.

Encryption
Network security
  • Configure firewall rules to restrict access to database ports.

  • Use network segmentation to isolate database nodes.

  • Implement SSL/TLS certificate validation.

  • Monitor network traffic for suspicious activity.

  • Use VPN or private networks for remote access.

Monitoring and compliance
  • Enable audit logging.

  • Monitor authentication and authorization events.

  • Track data access patterns.

  • Implement alerting for security events.

  • Regular security assessments and penetration testing.

  • Maintain compliance documentation.

Was this helpful?

Give Feedback

How can we improve the documentation?

© Copyright IBM Corporation 2026 | Privacy policy | Terms of use |  Manage Privacy Choices

Apache, Apache Cassandra, Cassandra, Apache Tomcat, Tomcat, Apache Lucene, Apache Solr, Apache Hadoop, Hadoop, Apache Pulsar, Pulsar, Apache Spark, Spark, Apache TinkerPop, TinkerPop, Apache Kafka and Kafka are either registered trademarks or trademarks of the Apache Software Foundation or its subsidiaries in Canada, the United States and/or other countries. Kubernetes is the registered trademark of the Linux Foundation.

General Inquiries: Contact IBM