Chapter 6. Securing Your Database
Securing Neo4j (and any other database, for that matter) is of paramount importance. Your database is likely to contain business-critical and sensitive data, including personal, financial, and tactical information. A security breach by data thieves can reveal information that could damage your business’s reputation and financial stability. Securing Neo4j is usually necessary to meet regulatory and compliance standards—a breach could even lead to a legal censure. Graph databases, in particular, can reveal crucial patterns and insights; unauthorized or malicious modification of the data may lead to misleading or incorrect predictions or results.
Tip
Security is always a top priority at Neo4j. We advise that you keep aware of the latest features in this area by visiting the release notes frequently.
As part of its compliance process, ElectricHarmony has brought in a team of security experts to conduct a threat analysis study of their system. They will adopt the STRIDE threat-assessment model, a structured framework for identifying and mitigating security threats. STRIDE is a mnemonic for security threats in six categories: spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. This chapter is structured along that framework, assessing each type of threat in turn. You will represent the Neo4j database team at ElectricHarmony and tag along with the experts to help them identify and mitigate potential ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access