Storage Daily
Security Daily
Networking Daily
FREE NEWSLETTERS
search
 

follow us on Twitter


internet.commerce
Be a Commerce Partner















internet.com
IT
Developer
Internet News
Small Business
Personal Technology

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers


Storage Products
 Atlantis Data Space Analyser (Atlantis Interactive UK Ltd.)
 ESBProgCalc Pro - Programmers Calculator (ESB Consultancy)
 Atlantis Schema Inspector (Atlantis Interactive UK Ltd.)
 MyCourts (Aquarius Communications)
 DocPoint - Document Management Software (Do It! Software Ltd.)
 Document Import Kit for SharePoint 2003 (Vyapin Software Systems Pvt Ltd.,)
» Enterprise IT Planet » Storage » Storage Features

Getting Beyond M&M SANs

By Drew Robb
December 22, 2003

Email Print Digg This Add to del.icio.us
"Most SANs are like M&Ms" hard and crunchy on the outside and soft on the inside.

This observation on Storage Area Network (SAN) design is from Clement Kent, the Chief Technical Officer of security firm Kasten Chase, Inc. He makes a vital point. Companies spend precious resources hardening the outer network shell with firewalls, passwords, certificates and keys, but the center, the actual data, is as insecure as ever. Let's take a look at what it takes to secure a SAN all the way from the edge to the core.

Keep the Shell Hard

Opening the enterprise data farm to company users in far-flung offices makes data more usable and more valuable, but far more vulnerable. Hackers and crackers continue to probe industrial defenses using new attack technology. Clearly, then, it is essential to deploy the latest developments in intrusion detection, firewalls, hardened switches and routers, and management systems. Storage administrators must not make the mistake of leaving everything to network personnel. At the very least, they must stay current with perimeter defense technology and wage a constant funding campaign for new tools and upgrades.

Harden the Core

Imagine the consequences if a criminal walked off with the daily backup tapes. Blackmail, class-action lawsuits and corporate train wrecks are real possibilities. Storage personnel must take the viewpoint that the bad guys will succeed sometime, so steps must be taken to minimize the value of what they obtain. This viewpoint is the first step toward real SAN security. If the data on the stolen backup tapes is encrypted, the criminal gains nothing and the company is safeguarded.

Storage encryption technology is not absolutely perfect, however, and SAN architects should not delude themselves by thinking otherwise. Given time and teraflops, a criminal can even beat 128-bit encryption. But storage encryption wraps the data in yet another protective layer and hardens the core of any SAN. Storage encryption appliances such as the Decru Data Fort, Kasten Chase Assurency SecureData and NeoScale Systems CryptoStor provide security without a costly performance hit. Using separate keys for data compartments can create an access control layer on top of the hardware zoning and LUN masking underneath.

Centralize Command

Security is everyone's responsibility, but unless one person is given the responsibility and authority to oversee all areas of corporate security, the company will have gaps in the coverage. A single appointed security manager can bridge the gap between network security and storage security specialists. Make the security manager the security policy approver, so that all conflicting procedures can be resolved and gaps between boundaries can be covered. Solicit input from Human Resources, so security policies have real teeth and unpleasant consequences for employees who slide off the straight and narrow. Obtain corporate buy-in to spread security awareness and responsibility to all parts of the company. This is vital as end-to-end SAN security does not come cheap.

Page 2: Audit Often

Go to page: 1  2  Next  

Email Print Digg This Add to del.icio.us

Storage Features Archives







Latest Forum Thread
     Enterpriseitplanet Forum
Topic By Replies Updated
HP EVA4400 Vs. EMC NS120 olivierb 1 2-9-2010 03:49 PM
Centera cenUsr 0 2-9-2010 03:49 PM
Literature STORAGE in VC! Goran_25 2 1-7-2010 02:44 PM
Refurbished EMC CLARiiON Drives DaryllChen 2 1-7-2010 02:43 PM
HDD seen as Cd Rom shakir69 1 12-31-2009 09:13 AM




The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers