What are some common mistakes and oversights when implementing storage encryption?

What are some common mistakes and oversights when implementing storage encryption?

The first one that comes to mind is the assumption that if it's encrypted, then it's secure. I think this is a dangerous mindset. You know, encryption doesn't automatically mean security. It's all in how the encryption is implemented and managed. That's the big one, and I tend to see that most with management and less technical people. They hear that they've got laptop encryption or that they've got a hardened data center and they assume that all is well, but that's hardly ever the case. You actually have to validate that with tools and ethical hacking techniques.

    Requires Free Membership to View

    When you register for SearchStorage.com, you’ll also receive targeted emails from my team of award-winning editorial writers. Our goal is to keep you informed on the hottest topics, the latest news and the biggest challenges you face as a storage professional today.

    Rich Castagna, Editorial Director

    By submitting your registration information to SearchStorage.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchStorage.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

Storage security information
Compression, deduplication and encryption: What's the difference?

Mobile device security in six simple steps

Five must-have storage security testing tools
I would also say there is a mindset that compliance doesn't really affect us. But, especially with regard to storage, compliance affects all of us in some fashion. Even if your industry isn't governed by a particular law or industry regulation, it still affects you in a downstream fashion through a business associate, a partner, service level agreement (SLA), etc. So, compliance has to be on your radar and management's radar.

Also, in most networks that I'm seeing, people don't have a clue as to what information they actually have. They also don't have a clue where it's stored or what security risks it's up against. So, if they don't know this stuff, they can't reasonably know what needs to be protected. I think the assumption is that everything that is sensitive is on servers or protected storage so there's not that much to worry about. This is wrong. I'm seeing vulnerabilities in these areas all the time. In any given network today, there are megabytes, if not gigabytes, of files scattered all across different hard drives and storage systems within the network. I think sensitive information is everywhere across the network, it's unprotected, and it's waiting to be compromised. And, a lot of people are oblivious to it in many cases.

Check out the entire Storage Encryption FAQ guide.


This was first published in October 2007