Basic Database security?

I'm working on a holiday booking website using c# , which uses a few databases for an assignment. One of our set objectives is to ''Implement basic database security'' Its been deliberately left open ended for us so I'm just wondering what kind of basic security could I implement?

It could be many things from prevent Sql Injection, allow access with a user name and password hashed and salted to roles and permissions. Sorry but the question is too vague.
This isn't the place for this type of question. I think even DBA Stack would downvote this without any prior research.
Basically don't use sa account.

