| Explore the TechTarget Network at SearchTechTarget.com. | |||
![]() |
![]() |
|
|
|
![]() | |
![]() | |
Additional Columns Features
Tools, Trends & Analysis
|
|
by: Stephen Foskett Issue: Jun 2003
Lately, I've started seeing a flood of storage security products appear in development. At the same time, our customers have begun asking about security security management groups in storage area network (SAN) deployment planning. Clearly, concern about SAN security is on the rise, but what can be done?
Confidentiality, integrity and availability Security breaches are often assumed to involve someone gaining access to information, but can also involve disruption of operations. In general, the topic of security focuses on three areas, each with its own risks and responses:
Ensuring data integrity relies on much the same access controls just mentioned. Locking out access to data keeps it safe. But like confidentiality, integrity can be hard to measure because prying eyes and meddling hands can leave a seemingly intact copy of data behind. While modification of data can be far more insidious than a loss of availability, howls of users when systems fail make it difficult to avoid attacking the problem. But their howls will be louder if it's evident that a security breach caused the outage. Here again, access control is the key, but brute-force attack can be much more difficult to defend against.
Maintain your integrity Although not always recognized as a security-related task, ensuring availability in an FC fabric is common practice for storage designers and managers. Redundant fabrics, multiple data paths, redundant equipment and business continuance copies are commonly employed to improve availability in the event of mistakes and failures. There are also other potential paths for attackers: insecure hosts, backup tapes, retired hardware and inside jobs. Even the most secure SAN can't protect data once a connected host has been compromised. By far the most common breach of SAN integrity is caused by accidental misconfiguration, rather than malicious attack. Most SAN managers have seen cases where a host "stepped on" another host's SAN LUNs. Even if it hasn't happened to them, the storage and systems administrators I talk to are concerned, and employ techniques like LUN masking on the array and zoning on the fabric to prevent it. Every SAN should use these techniques to ensure data integrity, and offline backup copies are required to recover from data corruption. Next, to protect the confidentiality of your data, don't forget to secure your backup tapes. Every day, a complete image of your storage infrastructure is sent out the door. Are you sure those tapes went out with the right people?
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
![]() |
![]() |
|
Storage Magazine is part of the TechTarget portfolio of enterprise IT-focused media. © 2002-2005 TechTarget. All Rights Reserved. Read our Privacy Policy |
|||