---
name: cloud-databases-manage-scc
title: Managing security and compliance with Cloud Databases
description: Cloud Databases is integrated with the Compliance Manager to help you manage security and compliance for your organization.
last-updated: 2026-06-25
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/cloud-databases?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Managing security and compliance with Cloud Databases
{: #manage-security-compliance}

Cloud Databases is integrated with the Compliance Manager to help you manage security and compliance for your organization.
{: shortdesc}

With the Compliance Manager, you can monitor for controls and goals that pertain to Cloud Databases.

## Monitoring security and compliance posture with Cloud Databases
{: #monitor-cloud-databases}

As a security or compliance focal, you can use the Cloud Databases [goals](#x2117978){: term} to help ensure that your organization is adhering to the external and internal standards for your industry. By using the Compliance Manager to validate the resource configurations in your account against a [profile](#x2034950){: term}, you can identify potential issues as they arise.

All of the goals for Cloud Databases are added to the IBM Cloud Control Library profile, but can also be mapped to other profiles.{: note}

To start monitoring your resources, check out [Getting started with Compliance Manager](https://cloud.ibm.com/docs/security-compliance?topic-security-compliance-getting-started&format=markdown)

### Available goals for Cloud Databases
{: #cloud-databases-available-goals}

* **Check whether Cloud Databases is enabled with IBM-managed or customer-managed encryption.** All Cloud Databases instances are automatically encrypted at rest with IBM-managed keys. For more information, see [Key Protect Integration](https://cloud.ibm.com/docs/cloud-databases?topic=cloud-databases-key-protect&format=markdown).
* **Check whether Cloud Databases is accessible only through TLS.** All Cloud Databases connections use TLS/SSL encryption for data in transit. The current supported version of this encryption is TLS 1.2. 
* **Check whether Cloud Databases is accessible only by using private endpoints.** Customers can disable public endpoints at provision time. For more information, see [Service Endpoints Integration](https://cloud.ibm.com/docs/cloud-databases?topic=cloud-databases-service-endpoints&format=markdown).
* **Check whether Cloud Databases network access is restricted to a specific IP range.** For more information see [Context-based restrictions](https://cloud.ibm.com/docs/cloud-databases?topic=cloud-databases-cbr&format=markdown) or [Allowlisting](https://cloud.ibm.com/docs/cloud-databases?topic=cloud-databases-allowlisting&format=markdown).