Home > Storage Technology Tips > Data storage management > The compliance payoffs for securing vulnerable information at rest
Storage Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

DATA STORAGE MANAGEMENT

The compliance payoffs for securing vulnerable information at rest


Kevin Beaver, CISSP
10.27.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


What you will learn from this tip: Trying to find good reasons to secure information at rest can be difficult -- even in the name of regulatory compliance. In this tip, information security expert Kevin Beaver highlights several business needs associated with securing data at rest that can help justify your efforts and storage-related security expenditures.

Most organizations, large and small, are affected by some type of law or regulation dealing with information privacy and security. As I've highlighted in a previous tip, some of the greatest security risks revolve around information at rest. When it's all said and done, virtually every information privacy and security law and regulation in the U.S., Canada, Europe and elsewhere requires in some way that sensitive information at rest (health information, financial information, financial reporting information, etc.) be protected in reasonable ways. It's really the most fundamental of all protection requirements.

Whether the threat comes in the form of malicious insiders, malware or hackers, businesses can't afford to not protect this information. There's simply too much too lose -- especially when it comes to some of the severe fines and jail time associated with noncompliance with recent regulations.

Various proven safeguards and countermeasures exist for the protection of information at rest, but you can't really implement and manage them effectively without some business justification. Ideally, business needs and risk management should drive the need for information security -- not solely regulatory compliance requirements. In fact, recent surveys show that regulatory compliance



is less of a driver for security spending than many anticipated.

Regardless, it's got to be done sooner or later. Here are some business-focused benefits of compliance you can use to sell security within your organization and show that value can be attained by ensuring the proper controls are in place for sensitive information at rest:

I'm a big advocate of keeping things simple and practical. Perfecting the security of your data at rest is not necessary at first and will likely prove elusive moving forward. I challenge you to spend your efforts and budget wisely on the latest 'compliant-ready' products and spend more on the security controls you already have at your disposal.

Focus on the areas that need the most attention (likely the corralling of stray information and improper file permissions) and then create a good plan, show that progress is being made and drill down over time. This will show that your organization is doing the right thing, keep employees on the up and up and help executives stay out of trouble. These are payoffs you can't refuse.

For more information:

Storage vulnerabilities you can't afford to miss


About the author: Kevin Beaver is an independent information security consultant, author, and speaker with Atlanta-based Principle Logic, LLC. He has more than 17 years of experience in IT and specializes in performing information security assessments. Kevin has written five books including "Hacking For Dummies" (Wiley), the brand new "Hacking Wireless Networks For Dummies," and "The Practical Guide to HIPAA Privacy and Security Compliance (Auerbach)." He can be reached at kbeaver @ principlelogic.com.


Rate this Tip
To rate tips, you must be a member of SearchStorage.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Data storage management,   Data Storage Management,   Data storage compliance and archiving,   Data storage compliance,   Data Storage Basics,   Data storage management,   Secure data storage,   Data Protection,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Data storage management
Choosing a storage system for data archiving
Green storage best practices control costs, increase energy efficiency
Best practices for using server virtualization in your storage environment
Best practices for effective thin provisioning
Three tips for ensuring a user-friendly email archiving system
Top tips when evaluating a storage automation product
Guidelines for implementing virtualization in your storage infrastructure
The value of easy-to-use SAN storage
Pros and cons of storage capacity management tools
What are the differences between SATA II vs. SATA I?

Data storage compliance and archiving
Choosing a storage system for data archiving
Mimosa Systems adds case management tool to NearPoint 4.0 data archiving software
Mimosa NearPoint, LiveOffice Mail Archive offer hybrid SaaS email archiving approach
HP resizes its ExDS9100 scale-out NAS system; finds market broader than original Web 2.0 target
New data archiving products focus on software-only delivery, cloud integration
Email archiving strategies: Five best practices
Email archiving needs soar as e-discovery requests rise
Storage Decisions Chicago 2009 Session Downloads
Storage Decisions Session Downloads: Data Retention & Retrieval Track (Chicago 2009)
Storage Decisions Session Downloads: Storage Systems & Storage Management Track (Chicago 2009)
Data storage compliance and archiving Research

Data storage compliance
Are you ready for new compliance rules?
Storage IQ: Compliance
Data storage compliance's impact on storage product choices
Understanding compliance: Beyond data protection
Archiving unstructured data
Choosing a compliance archiving tool

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
litigation hold  (SearchStorage.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Find Data Backup Analysis and Server Storage Channel Solutions

The Data Domain Data DeDuplication Center - Data Retention, Replication and Recovery

TechTarget Storage Media
Storage Magazine View this month\\'s issue and subscribe today.
Storage Decisions Apply online for free conference admission.
SearchStorage.com
HomeNewsMagazineTopicsLearningMultimediaWhite PapersBlogsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts