Security of Database Systems and Cloud Computing 2100-CB-M-D3BSBD
The course introduces the fundamentals of relational and non-relational database systems and their importance to information security. It covers common threats, including unauthorized access, excessive privileges, configuration weaknesses, insecure credential management, and insufficient activity monitoring.
A significant part of the course will be practical. In controlled laboratory environments, students will identify and analyze vulnerabilities occurring between applications and databases, with particular emphasis on SQL injection. They will also learn how to prevent such vulnerabilities, including the use of parameterized queries and secure privilege management.
Practical exercises will cover selected aspects of database security, including user and role configuration, the principle of least privilege, limiting service exposure, encryption, secure backup management, event logging, and basic security configuration assessment.
The course will also provide a general introduction to cloud security. It will cover cloud service models, the shared responsibility model, identity and access management, data protection, network security, monitoring, and common configuration weaknesses. At the end of the semester, students will complete a project applying the acquired knowledge in practice.
|
Term 2025Z:
Participants will be introduced to the threats that occur when working in the cloud and using databases. They will be presented with the most commonly used database systems. The most common threats will be discussed. Topics such as data encryption and backup will also be covered. Methods of securing data and preventing data loss will be presented. At the end of the semester, students will be required to complete a project to apply the knowledge they have acquired in practice. |
Course coordinators
Term 2026Z: | Term 2025Z: |
Type of course
Mode
Prerequisites (description)
Learning outcomes
KNOWLEDGE:
K_W03 - The graduate knows and understands behaviors affecting the security of database systems and cloud computing and has knowledge of how to ensure security when using these technologies.
K_W06 - The graduate knows and understands the principles of information security when using database systems and cloud solutions, including the principles of physical, software, and network controls, as well as monitoring and securing databases against breaches of their confidentiality, integrity, and availability. The graduate also knows the methods of protecting data, database management systems, and applications that access and use the data.
K_W09 - The graduate knows and understands the strategies for implementing security controls in database systems and cloud solutions, conducting risk assessments, and handling the detection and response to incidents in cloud-based environments.
SKILLS:
K_U03 - The graduate can independently explain and utilize basic techniques and technologies to ensure the security of database systems and cloud solutions.
SOCIAL COMPETENCES:
K_K01 - The graduate is ready to promote the need to reduce risk and foster responsible attitudes regarding the use of database systems and cloud solutions, and to disseminate the importance of this knowledge in critically addressing cybersecurity issues in social and economic life.
Assessment criteria
Project
Level of AI use:
– Level 2: AI-GENERATED IDEAS AND STRUCTURE (Artificial intelligence may be used, among other things, for brainstorming, developing the structure, and generating ideas for improving the work. The final version of the work must not contain any AI-generated content.)
Practical placement
N/A
Bibliography
Primary literature
Hao Q., Tsikerdekis M., „Relacyjne bazy danych. Ilustrowany przewodnik”, Helion, 2026. [PL]
English version: Hao Q., Tsikerdekis M., „Grokking Relational Database Design”, Manning Publications, 2025. [EN]
Dotson C., „Bezpieczeństwo w chmurze. Przewodnik po projektowaniu i wdrażaniu zabezpieczeń”, Wydawnictwo Naukowe PWN, Warszawa 2020. [PL]
English version – newer, second edition: Dotson C., „Practical Cloud Security: A Guide for Secure Design and Deployment”, 2nd Edition, O’Reilly Media, 2024. [EN]
Supplementary literature
McNab C., „Ocena bezpieczeństwa sieci”, 3rd Edition, APN Promise, 2017 – in particular Chapter 15 on assessing data stores. [PL]
English version: McNab C., „Network Security Assessment”, 3rd Edition, O’Reilly Media, 2016 – in particular Chapter 15: „Assessing Data Stores”. [EN]
OWASP Foundation, „Database Security Cheat Sheet”, available online:
https://cheatsheetseries.owasp.org/cheatsheets/Database_Security_Cheat_Sheet.html [EN]
OWASP Foundation, „SQL Injection Prevention Cheat Sheet”, available online:
https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html [EN]
OWASP Foundation, „Secure Cloud Architecture Cheat Sheet”, available online:
https://cheatsheetseries.owasp.org/cheatsheets/Secure_Cloud_Architecture_Cheat_Sheet.html [EN]
PortSwigger, „SQL Injection”, Web Security Academy, learning material and practical labs, available online:
https://portswigger.net/web-security/sql-injection [EN]
Bridging materials
Pasja Informatyki, „Kurs MySQL. Bazy danych, język zapytań SQL”, video course available online:
https://www.youtube.com/playlist?list=PLOYHgt8dIdoymv-Wzvs8M-OsKFD31VTVZ [PL]
This material is optional and intended for students who have no prior experience with relational databases or SQL.
|
Term 2025Z:
"Privacy and Security for Cloud Computing", S.Pearson, G.Yee (red.), Springer-Verlag London 2013. |
Term 2026Z:
Primary literature Hao Q., Tsikerdekis M., „Relacyjne bazy danych. Ilustrowany przewodnik”, Helion, 2026. [PL] English version: Hao Q., Tsikerdekis M., „Grokking Relational Database Design”, Manning Publications, 2025. [EN] Dotson C., „Bezpieczeństwo w chmurze. Przewodnik po projektowaniu i wdrażaniu zabezpieczeń”, Wydawnictwo Naukowe PWN, Warszawa 2020. [PL] English version – newer, second edition: Dotson C., „Practical Cloud Security: A Guide for Secure Design and Deployment”, 2nd Edition, O’Reilly Media, 2024. [EN] Supplementary literature McNab C., „Ocena bezpieczeństwa sieci”, 3rd Edition, APN Promise, 2017 – in particular Chapter 15 on assessing data stores. [PL] English version: McNab C., „Network Security Assessment”, 3rd Edition, O’Reilly Media, 2016 – in particular Chapter 15: „Assessing Data Stores”. [EN] OWASP Foundation, „Database Security Cheat Sheet”, available online: OWASP Foundation, „SQL Injection Prevention Cheat Sheet”, available online: OWASP Foundation, „Secure Cloud Architecture Cheat Sheet”, available online: PortSwigger, „SQL Injection”, Web Security Academy, learning material and practical labs, available online: Bridging materials Pasja Informatyki, „Kurs MySQL. Bazy danych, język zapytań SQL”, video course available online: This material is optional and intended for students who have no prior experience with relational databases or SQL. |