Help Center/ Database Security Service/ User Guide/ Database Security O&M/ Series 2/ Introduction to Database Security Operations and Maintenance
Updated on 2026-08-04 GMT+08:00

Introduction to Database Security Operations and Maintenance

Product Overview

Database Operations and Maintenance Management is a data security product designed to enforce security controls over the operational activities of database maintenance personnel.

Database operations and maintenance leverage technologies such as unified login, permission management, multi-factor authentication, data anonymization, and operation approval to minimize permission controls for maintenance personnel, block risky operations, and enable behavior auditing.

Figure 1 Implementation process

Usage Scenario

The database operation and maintenance management is specifically designed for database operation scenarios, effectively addressing data security risks faced by database maintenance personnel during their work.

Figure 2 Application scenarios

Personnel Identity Authentication

Complete strong identity authentication through multi-factor authentication (MFA) and other methods, enabling traceable operation audits to individual users.

Controllable O&M Permissions

All O&M operations are subject to fine-grained authorization control, preventing user misoperations and risky actions to avoid data leakage.

Approval Required for Sensitive Operations

Operations involving sensitive tables and sensitive fields are subject to mandatory approval workflows, with data desensitization applied automatically.

Comprehensive Operation Logging

All operations performed by O&M personnel on all databases are recorded in tamper-proof, independent logs, supporting centralized auditing.

Product Superiority

The database operations and maintenance management system offers advantages including support for diverse database types, fine-grained operation and maintenance permission control, centralized identity management, multi-dimensional monitoring, comprehensive security policies, and support for High Availability (HA).

Comprehensive Database Protocol Support

The database operation and maintenance management system supports not only mainstream databases such as MySQL, Oracle, SQL Server, PostgreSQL, and DB2, but also various domestic, specialized, and big data databases, fully meeting data security requirements across diverse industries and business scenarios.

Fine-grained and Operational Permission Management

The database operations and maintenance management system implements access control based on three dimensions: subject conditions, object scope, and access behaviors, with each category further subdivided into multiple sub dimensions. With over a hundred policy combinations available, the system enables precise security protection at various data levels.

  • The granular level can be refined to operational users, roles, organizational units, database users, time periods, and more.
  • The object granularity can be set for rows, columns, and other properties.
  • Behavior granularity desensitization operations, blocking operations, SQL statements, etc.
Figure 3 Permission Management

Flexible Protection Targets and Policies

The database operations and maintenance management system supports multi-dimensional control of data assets. Through policy configuration, users can flexibly define protected entities—including databases, tables, fields, records, keywords, and conditions. Strict control policies can be applied to these entities: modifications, deletions, or even visibility restrictions require prior approval.

Product Function

This section introduces the main functions of the database operations and maintenance management system.

Feature

Description

Reference

Home page

This page provides centralized visibility into the three core security modules: data access permission control, dynamic data masking, and O&M bastion host operations.

Homepage Information

O&M asset management

You can add, edit, and delete assets. On the Ops Asset Management page, you can manage O&M asset library accounts and review their access permissions. Identity- and condition-based security policies are supported for Ops Asset Control, including sensitive data masking, high-risk operation blocking, row-level access control, SQL replacement, blacklist and whitelist, and audit.

O&M Asset Management

User management

The built-in system administrator, security administrator, and security auditor roles support a strict separation of duties. They provide a system of checks and balances, preventing data leakage caused by excessive permissions.

User Management

Rule management

You can manage built-in rules, including discovery rules and masking rules. You can also create custom rules.

Rule Management

Behavior audit

Audit logs capture the characteristics of access events to fully reconstruct user behavior.

In addition to platform operation logs, they record all service data access events initiated by O&M personnel.

Behavior Audit

System management

You can monitor device information and status, manage devices, analyze the utilization of system memory, CPUs, storage, and network traffic, perform system upgrades, and configure system time.

You can manage NICs, and easily export or import configuration files for rapid backup and restoration.

System Management

O&M bastion host entry

Through the O&M entry point, management personnel can launch a new page to complete routine administrative tasks using the WebSQL tool.

During database O&M, a database operator can submit a service ticket. Once approved, the operator can perform authorized database operations through the WebSQL client.

O&M Bastion Host Entry

Deployment Method

The database operations and maintenance management system supports proxy deployment. The proxy can be deployed via physical bypass or logical serial methods.

The system integrates with the database operations and maintenance management platform online, enabling maintenance personnel to directly access the device addresses and ports of the platform. Serving as an intermediate node, the platform processes and forwards network traffic.

Figure 4 Agent deployment