Database security checklist
This list summarizes features, recommendations, and best practices for implementing HCD security features on your clusters and databases. For more information about the HCD security architecture, see HCD security overview.
- Authentication and authorization
-
-
Enable authentication on all nodes:
-
Internal: Username/password pairs stored in the internal database. Use strong passwords for internal authentication.
-
LDAP: External LDAP service integration, such as Active Directory or OpenLDAP.
-
OpenID Connect (OIDC): Modern identity providers for enterprise SSO.
HCD authentication is only supported for database connections.
-
-
-
Create admin roles and users.
-
Create specific roles for different user types.
-
Grant minimum necessary permissions.
-
-
Create a non-default superuser role, and then disable the default
cassandrarole. -
Regularly review and update role assignments.
-
- Encryption
-
-
Enable client-to-node encryption for all connections.
-
Enable node-to-node encryption for internode communication.
-
Use strong cipher suites and TLS 1.2 or higher.
-
Implement Transparent Data Encryption (TDE) for sensitive data, including SSTable files, commit log files, and hints files.
-
Use key management.
-
Regularly rotate encryption keys.
-
- Network security
-
-
Configure firewall rules to restrict access to database ports.
-
Use network segmentation to isolate database nodes.
-
Implement SSL/TLS certificate validation.
-
Monitor network traffic for suspicious activity.
-
Use VPN or private networks for remote access.
-
- Monitoring and compliance
-
-
Enable audit logging.
-
Monitor authentication and authorization events.
-
Track data access patterns.
-
Implement alerting for security events.
-
Regular security assessments and penetration testing.
-
Maintain compliance documentation.
-