"the DoD/DISA "Security Technical Implementation Guide" (STIG) is available as a pdf download and covers security for Oracle, DB2 and SQL Server.
It's pretty comprehensive and ought to be a reasonable reference for those starting out with database security."
The document is available from http://iase.disa.mil/stigs/stig/database-stig-v7r1.pdf.
I have not been able to download it myself yet as I am stuck in an internet club at Munich airport waiting for check-in to open for my flight home. If anyone has any useful comments on it I would be glad to hear in the forum thread above. Thanks again David for letting us know.