SQL Server is regularly targeted by hackers as it is a repository of sensitive data for organizations. If breached, hackers can gain access to confidential information including, but not limited to credit card numbers, social security numbers, and marketing information. This presentation covers topics pertaining to best practices and tips on how to secure and harden a SQL Server 2008 & 2005 implementation. Some of the security and hardening topics covered include: minimize surface area with policy based management, encryption, advanced auditing, configuring a Windows Server 2008 firewall, applying security templates with Active Directory, and consolidating SQL Server logs.