Home > Storage Technology Tips > Data storage management > A two-dimensional approach to storage security
Storage Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

DATA STORAGE MANAGEMENT

A two-dimensional approach to storage security


Vijay Ahuja
02.16.2004
Rating: -3.50- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Just like any other network, storage networks should be secured using a layered approach. Storage security can be viewed as the act of protecting stored data through multiple layers of safeguards. In this column, I outline a two-dimensional layered approach for storage security.

Storage network security can be designed as a multiple layer model consisting of two dimensions -- the storage network layers and the security safeguards for each layer. First, storage environments can be secured by addressing each layer of the storage network as outlined next.

Application layer is the highest layer. An application may implement security within the application, thereby providing end-end security.

Management layer is the next layer and provides management of the storage network. This layer should implement its own security so the management data is not exposed to external attacks, both while in transit and in store.

File layer offers the next layer for security. Storage data may be secured by securing the entire files.

Block layer provides the lowest layer for securing data. Block-level security ensures that each block of data can be secured independent of the other blocks.

A separate dimension is to implement different security technologies for each layer. There are several steps or layers for deploying safeguards at each of the above storage network layers.

First step is to secure the environment by implementing intrusion prevention and filtering (read "anti-virus" and "firewall") technologies. This should prevent entry of viruses and other denial of service attacks.

Next, you may deploy access controls to storage components. This would include the role based access control and similar schemes to restrict access to unauthorized resources in the storage network.

As the next step, you may implement strong authentication for various storage components and related entities. In this way, you can prevent some of the spoofing attacks.

Finally, you may implement confidentiality by encrypting the data at the given layer.

Securing storage environment is not the simple process of selecting a technology and deploying it across the storage network. You need to evaluate security risks at each layer, and apply corresponding security safeguards for each layer. There is no one-size fit-all for storage network security.

Rate this Tip
To rate tips, you must be a member of SearchStorage.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Security,   Administrative Tools and Strategies,   General,   General,   Enterprise Storage Management,   General,   Enterprise Storage Planning,   Data storage management,   Secure data storage,   Data Protection,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Security
Time to try storage smart cards?
Making DMZ isolated networks safe
Storage under attack
Storage security starts with data protection
Determining data protection needs

General
Helpful hints when expanding or moving your data
Where to focus your compliance efforts
SRM keeps your storage clean
What compliance means for peripheral storage
Compliance tools you should be requesting from vendors
Who's going to be responsible for compliance -- vendors or end users?
Building a four-node SAN cluster
The best technique for disaster recovery
Why a NAS gateway?
NAS gateway products for 2004

General
SAN School: Final quiz:
ISCSI and FC tools, where are you?
E-mail management derailed by regulations
Why you need to care about standards
Make sense of SAN management software
Using NAS for database storage
Beyond storage: 12 types of critical disaster recovery teams
How many admins does it take to manage a terabyte?
The best method for migrating from Symmetrix to DMX
SAN vs. NAS file sharing

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Find Data Backup Analysis
TechTarget Storage Media
Storage Magazine View this month\\'s issue and subscribe today.
Storage Decisions Apply online for free conference admission.
SearchStorage.com
HomeNewsMagazineTopicsLearningMultimediaWhite PapersBlogsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts