Top five security questions to ask storage vendors

Top five security questions to ask storage vendors

When soliciting vendors for storage management solutions, what are the top five questions to ask them about security as it relates to storage?

    Requires Free Membership to View

    When you register for SearchStorage.com, you’ll also receive targeted emails from my team of award-winning editorial writers. Our goal is to keep you informed on the hottest topics, the latest news and the biggest challenges you face as a storage professional today.

    Rich Castagna, Editorial Director

    By submitting your registration information to SearchStorage.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchStorage.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

1. What type of authentication are you supporting? The T11 FC SP draft recommends support of DH CHAP with RADIUS server.

2. What type of encryption is used to secure traffic between the management entities? They may use SSL, SSH and in certain environments VPN/IPSec may help.

3. How the encryption keys are stored and secured?

4. How the secrets (e.g. passwords) are secured while in storage?

5. What kind of access control (RBAC etc.) is supported?

Remember that the management network has several components -- and you want to probe the security for each component: managed entity (switches, ports, etc.), management server, management admin workstation and the network over which they are connected. Also, the traffic may traverse over Fibre Channel (FC) or IP -- you need to address both.

There is a lot you, as the end user, can do. For starters, keep the corporate network and the storage management network separate.

This was first published in July 2005