Home > Storage Technology Tips > SAN/NAS Update > Seven ways to protect high-value information on SANs
Storage Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SAN/NAS UPDATE

Seven ways to protect high-value information on SANs


Rick Cook
01.30.2006
Rating: -3.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


What you will learn from this tip: Controlling access to your SAN, using hard zoning and establishing a good key management can keep your data safe. Learn more about these techniques and others in this tip.

Like any other network, SANs are vulnerable to attack. Below are seven precautions you can take to secure high-value information on your SAN.

1. Use a separate network for your SAN
One of the advantages of iSCSI storage is that it can use your LAN, reducing the costs. However, if you're concerned about security, you're better off having a physically separate network for your SAN alone.

2. Use hard zoning
With hard zoning, access to the zone is physically blocked. While hard zoning is not as convenient as soft zoning for subdividing a LAN, it is more secure.

3. Control access to your SAN
This doesn't just mean having the appropriate access controls on users -- it means having the proper security for the SAN itself. Many SAN switches and HBAs have external connections for remote maintenance and troubleshooting. That's handy in the normal course of things, but it opens a gaping security hole. In theory, a black hat could use that maintenance port to get into your switch and compromise your system. Most of the devices that allow remote access also let you turn that feature off.

4. Manage and log changes to your SAN
It's important to secure the management function of your SAN. Unauthorized changes to the configuration, port assignments, ACLs or device lists can leave even the best designed SAN vulnerable. Some companies, such as Brocade, offer SAN operating systems specially designed for security. Most modern SAN management tools have features to prevent unauthorized changes and to securely log any changes that are made.

5. Encr



ypt your data over the SAN
Whether you are using an iSCSI or Fibre Channel SAN, encrypting sensitive data is an important security measure.

Please note that some encryption programs, such as Microsoft Corp.'s Encrypting File System (EFS), automatically decrypt data before sending it over the network. EFS and similar products are only designed to protect your data while it is stored on disk, not while it is in transit. Products such as Assurency SecureData from Kasten Chase Applied Research Limited encrypt data moving over the SAN.

If you decide to encrypt data make sure you have an effective, secure and tested key management system in place before you begin encryption. An encryption system is only as secure as its keys and an encryption system without a method for recovering lost or damaged keys is an invitation to data loss.

6. Consider physical security
Don't neglect the physical security of the SAN switches or the storage. Server and switch locations should have access control to prevent unauthorized people from gaining access to the equipment.

7. Weigh your risks
The most important principle in any kind of security is weighing the risks against the benefits of proposed security measures. How much security you need depends very much on the value of what you are trying to protect. This kind of cost/benefit analysis is especially important when considering the purchase of equipment such as SAN encryption devices.

Do you know…


About the author: Rick Cook has been writing about mass storage since the days when the term meant an 80 K floppy disk. The computers he learned on used ferrite cores and magnetic drums. For the last 20 years, he has been a freelance writer specializing in storage and other computer issues.


Rate this Tip
To rate tips, you must be a member of SearchStorage.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Storage Area Network,   Storage area network monitoring/troubleshooting,   Storage area network management,   SAN/NAS Update,   SAN management,   SAN (storage area network),   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Storage area network monitoring/troubleshooting
SAN security benefits
SAN fine tuning: Get the most from your storage
RAID technology adds reliability and overcomes concerns
Risk management: Know your storage risks
Cannot retrieve data from RAID

SAN/NAS Update
Storage-area networks to become increasingly object based
Reducing storage network complexity with FCoE
Clustered storage essentials: What to ask your vendor
The value of easy-to-use SAN storage
SAN storage consolidation checklist
Pros and cons of using NAS NFS with VMware
A case for 8 GB Fibre Channel
Wide stripe before you dive into SSD
How to determine a NAS system's scalability
Top five SAN tips of 2008

SAN management
Storage Decisions Chicago 2009 Session Downloads
Storage Decisions Session Downloads: Managing Storage Networks Track (Chicago 2009)
Storage-area networks to become increasingly object based
Data storage management in virtual server environments
10 Gb Ethernet bodes well for iSCSI
Mellanox builds bridge to consolidation
Best storage Products of the Year 2008
Wide stripe before you dive into SSD
How your SAN will evolve
New realities of green IT: STORAGE BIN 2.0
SAN management Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Fast Guide to Storage Technologies  (WhatIs.com)
fat provisioning  (SearchStorage.com)
oversubscription  (SearchStorage.com)
RAID  (SearchStorage.com)
storage area management  (SearchStorage.com)
storage area network  (SearchStorage.com)
thin provisioning  (SearchStorage.com)
unified storage  (SearchStorage.com)
virtual provisioning  (SearchStorage.com)
zoned-bit recording  (SearchStorage.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Find Data Backup Analysis and Server Storage Channel Solutions

The Data Domain Data DeDuplication Center - Data Retention, Replication and Recovery

TechTarget Storage Media
Storage Magazine View this month\\'s issue and subscribe today.
Storage Decisions Apply online for free conference admission.
SearchStorage.com
HomeNewsMagazineTopicsLearningMultimediaWhite PapersBlogsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts