Home > Storage Magazine > Features > Is encryption enough?
EMAIL THIS
Storage Magazine

  CURRENT ISSUE  

  FEATURES  

  TOOLS, TRENDS & ANALYSIS  

  COLUMNS  

  ARCHIVES  

  SUBSCRIBE/RENEW  
 

Is encryption enough?
by Alan Radding
Issue: Jun 2006
printer-friendly
< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   6  |   NEXT PAGE  >

Management tools are accessed through servers that connect directly to the SAN. "The Achilles' heel of SAN security is that the management interfaces to the storage devices are sitting on the corporate LAN," says W. Curtis Preston, vice president of data protection at GlassHouse Technologies Inc., Framingham, MA. At a minimum, he says, managers should regularly change the passwords to management tools.

Establishing effective access control for storage is problematic at this point. "No one has strong role-based access control, the kind that will let you control access at the command line," says SNIA's Budnik. He expects such role-based security to emerge over the next two years.

In addition to access control is identity management. Storage managers, however, can't do much on their own about identity management. "The tools are mainly in the application stack," says TheInfoPro's Stevenson. "Storage people often see identity management as the re...



sponsibility of the DBA or application developers."

This kind of finger-pointing is typical of the breakdowns that lead to security breaches. The solution calls for storage, corporate security, network and application teams, and business managers to work out a set of policies and procedures together.

"What we've seen is that policies are the key to security," says Jot Gill, an information management consultant now building a strategic consulting practice at Network Appliance Inc. "This is not a device layer issue or an application layer issue--it is a business issue." Such a policy effort, he adds, should even include input from--heaven forbid--lawyers and accountants.

This requires cooperation among all players. "The struggle we're seeing with our customers is who drives the policy," says Forsythe's Arland. "The storage people can take some basic security measures, but you really need an overall security policy on the corporate level."

< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   6  |   NEXT PAGE  >





TechTarget Storage Media
Storage Magazine View this month\\'s issue and subscribe today.
Storage Decisions Apply online for free conference admission.
SearchStorage.com
HomeNewsMagazineTopicsLearningMultimediaWhite PapersBlogsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts