Home > Storage Magazine > Columns > Hot Spots
EMAIL THIS LICENSING & REPRINTS
Storage Magazine

  CURRENT ISSUE  

  FEATURES  

  TOOLS, TRENDS & ANALYSIS  

  COLUMNS  

  ARCHIVES  

  SUBSCRIBE/RENEW  
 

Hot Spots
by Jon Oltsik
Issue: May 2006
printer-friendly
licensing & reprints
< PREV PAGE   |   1  |   2  |   3  |   NEXT PAGE  >

Storage security focus for 2006

Storage security turned a corner in 2005. Now it's time for storage pros to get serious about security.

AS FAR AS I'm concerned, 2005 was a watershed year for storage security. EMC announced to the world that, moving forward, security would be integrated into the company and its products. Network Appliance voted with its wallet by acquiring Decru. Tape leaders such as Quantum and Spectra Logic added encryption capabilities to their systems.

Storage security victory! Well ... not quite.

Don't get me wrong. After three years of carrying on about storage security, it's great to see this new wave of progress ripple through the industry. In spite of this, IT storage managers and the storage vendor community still have a myopic view of security. Too many folks think the term "storage security" can be interpreted as either backup encryption or as a security appliance à la Kasten Chase or NeoScale.

So, my storage-centric brethren, when it comes to security there are a few things to keep in mind:

  1. Security must be systemic. Remember the television show Get Smart? At the beginning of each episode, Maxwell Smart (Agent 86) had to pass through a number of security checkpoints before arriving in his office. In this vintage TV example, each checkpoint is another "layer" of security, a model often referred to as "defense-in-depth." Storage security is no different; to be truly effective, encryption must be supported with things like access controls, strong authentication and monitoring.


  2. Security threats are always changing. Think about all the stuff you have to guard against on your PC: viruses, worms, spam, phishing, etc. The bad guys are discovering new attack vectors all the time. This means that the storage community has to remain in a constant state of security awareness. You have to make patching management servers and monitoring bug-tracking sites a priority, and ensure your staff is trained to know a scam when they see one.


  3. You can't manage (or in this case, secure) what you can't measure. I know this is a tired old business saying that everyone has heard from some dorky boss, but with security it's certainly a truism. If I don't capture baseline information, monitor changes and offer all this information up as reports, how can I tell how secure my storage is?
< PREV PAGE   |   1  |   2  |   3  |   NEXT PAGE  >




TechTarget Storage Media
Storage Magazine View this month\\'s issue and subscribe today.
Storage Decisions Apply online for free conference admission.
SearchStorage.com
HomeNewsMagazineTopicsLearningMultimediaWhite PapersBlogsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts