One of the most important best practices is to search MSDN for examples of "SQL parameters", you capture user data and store them in parameters and then incorporate the parameters into the SQL query. Parameters protect your database from hackers looking to get into your database records. Another important security related feature to check on is to look up "stored procedures". Again, it keeps your database queries better protected, so that your code behind simply makes a reference to a stored procedure for your application instead of having SQL in the actual C# code.
-------------------------
Whatever you can do or dream you can, begin it. Boldness has genius, power and magic in it. Begin it now.
-Johann von Goethe
When Two Hearts Race... Both Win.
-Dove Chocolate Wrapper
Chroniclemaster1, Founder of
www.EarthChronicle.com
A Growing History of our Planet, by our Planet, for our Planet.