Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Security Issues in the Database Language SQL

Published

Author(s)

William T. Polk, Lawrence E. Bassham

Abstract

The Database Language SQL (SQL) is a standard interface for accessing and manipulating relational databases. An SQL-compliant database management system (DBMS) will include a minimum level of functionality in a variety of areas. However, many additional areas are left unspecified by the SQL standard. In addition, there are multiple versions of the SQL standard; the functionality will vary according to the particular version. This document examines the security functionality that might be required of relational DBMS's, and compares them with the requirements and options of the SQL specifications. The comparison will show that the security functionality of an SQL-compliant DBMS may vary greatly. A variety of security policies are considered which can be supported by SQL. The document ends by showing which types of functions are required by the examined security policies.
Citation
Special Publication (NIST SP) - 800-8
Report Number
800-8

Keywords

computer security, DBMS, relational database management system, SQL

Citation

Polk, W. and Bassham, L. (1993), Security Issues in the Database Language SQL, Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD (Accessed April 24, 2024)
Created August 2, 1993, Updated February 19, 2017