Home > Storage Technology Tips > > How to stop data thieves and old bad habits
Storage Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


How to stop data thieves and old bad habits


Maxine Kincora
08.23.2005
Rating: -4.50- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


What you will learn from this tip: Four storage experts explain why storage security has been overlooked and how administrators can keep thieves out of their storage resources.


"Security for storage has been ignored by storage administrators and everyone else in charge of IT security," says Jim Damoulakis, CTO of GlassHouse Technologies, Inc., based in Framingham, Mass.

Damoulakis' assessment comes on the heels of recent storage security breaches, including unencrypted backup tape thefts from Bank of America, sizeable backup tape losses at Ameritrade and Time Warner and theft of DSW Shoe Warehouse customers' credit card data. These headline-grabbing data losses have led to the introduction of Senate legislation, the Personal Data Privacy and Security Act of 2005, which puts the blame for customer data loss on corporate executives.

Historically, added security for storage was deemed unnecessary, because storage was done on relatively isolated standalone devices, according to Dennis Martin, senior analyst for storage management software and security at Greenwood Village, Colo.-based Evaluator Group. Since the physical connections of those devices to the hosts were hidden, they were difficult to find within a network. If an outsider couldn't get to the host, he or she couldn't get to the storage device or to the stored data.

Related information

EMC sketches out security strategy

Securing the tape custody chain

Compress, then encrypt tapes

With the advent of new storage technologies, storage is no longer so hidden. Fibre channel (FC) and iSCSI SANs are accessed and managed over IP connections, with all the attendant risks to which IP exposes networks.

"Islands of SANs within an environment have been considered low-risk areas," says Damoulakis. "However, the SAN infrastructure connects to hosts on the network. To do very serious damage would simply require working through a compromised host and getting access to this largely unsecured storage network."

Standard corporate network security practices -- such as password management, enforcing access controls, enabling audit trails, securing management interface points -- should all be applied to storage, the experts agree.

"Security for backup has also been very lax," says Jon Oltsik, senior information security and storage analyst at Enterprise Strategy Group, Milford, Mass. For example, Bank of America's backup tapes were stolen by baggage handlers while being shipped to another location on a commercial plane.

The fact that Bank of America's stolen data was unencrypted points to another historic oversight. "Typically, companies only do encryption on information in motion across the network from point A to point B," says Damoulakis.

Oltsik explains that encryption of stored data has been a duty shirked for two reasons; encryption slowed networks down to a crawl, and management of algorithms and keys is difficult.

The issue of bogging down performance is old news as far as Oltsik is concerned. "Encryption is a very processor-intensive activity, but it no longer slows backup because the processors are 10 times as fast as they once were," Oltsik explains.

According to Vijay Ahuja, president of Raleigh, N.C.-based Cipher Solutions, managing encryption is not the easiest task but is doable with simple best practices. The management of encryption keys should be carefully considered, with the security risks inherent in changes in personnel and company management taken into account. Ahuja counsels companies to review and test their encryption keys and algorithms on a regular basis.

Securing data may be a hassle but it's a job that can't be ignored anymore. The experts recommend taking a holistic approach to IT infrastructure, in which the security and storage teams work together to examine and secure the infrastructure as a whole.

Every best practice in security that's in place for the network should be implemented for storage. Here's the experts' list of some important best practices:

  • Audit and do a risk assessment on the storage infrastructure, looking for risks and vulnerabilities.
  • Implement authentication across the storage network. Ahuja advocates using the Diffie-Hellman Challenge Handshake Authentication Protocol (DHCHAP). "The beauty is that most Fortune 500 companies already have this protocol in their networks," says Ahuja.
  • Implement strong role-based access controls. Assign access rights to parties on a need-to-know basis.
  • Demand strong security from storage system vendors and offsite storage providers.
  • Adopt and enforce data encryption policies. Best practices include classifying data and applying encryption to private and confidential data through the lifecycle of the data. "You don't have to encrypt all data," says Oltsik, but sensitive data should be encrypted in flight and at rest.
  • Don't forget to secure your SAN at the switch or fabric level, says Martin. Carving up your fabric by zones is one technique that limits access to various parts of the SAN.
  • Create a policy for discarding old devices and media, routinely doing such tasks as scrubbing and destroying hard disks, Martin says.
  • Isolate your storage management network from your corporate IT network. "The storage management network has to be secure, since that network is connected to all of your devices," says Ahuja. "If you don't isolate the networks, every employee has access to your storage."
  • Treat backup as an "orange alert" process. Adopt secure media management tracking and handling policies. "Backup literally touches everything, every bit of corporate financial information, employee data and intellectual property," says Damoulakis.
  • IT shops can no longer afford to ignore the risks of leaving their storage unprotected. With common sense best practices in place, everyone can rest assured that corporate data is secure.

    For more information:

    Securing data at rest vs. data in transit


    Rate this Tip
    To rate tips, you must be a member of SearchStorage.com.
    Register now to start rating these tips. Log in if you are already a member.




    BROWSE BY TAG
    Secure data storage,   Data Protection,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Secure data storage
    Throwing caution to the clouds
    Storage encryption essentials
    Vendors take steps to lock down cloud storage services
    Encryption Special Report: Key management stumbling block to securing data
    What you need to know about storage encryption products
    Isilon targets enterprise NAS with Backup Accelerator, N+2:1 parity
    Storage Decisions Chicago 2009 Session Downloads
    Storage Decisions Session Downloads: Disaster Recovery Track (Chicago 2009)
    Storage Decisions Session Downloads: Data Retention & Retrieval Track (Chicago 2009)
    Data on the brink

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    hard drive shredder  (SearchStorage.com)
    Storage as a Service (SaaS)  (SearchStorage.com)
    storage encryption  (SearchStorage.com)
    storage security  (SearchStorage.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Find Data Backup Analysis
    TechTarget Storage Media
    Storage Magazine View this month\\'s issue and subscribe today.
    Storage Decisions Apply online for free conference admission.
    SearchStorage.com
    HomeNewsMagazineTopicsLearningMultimediaWhite PapersBlogsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts