Home > Ask the Storage Channel Experts > Storage Projects Questions & Answers > Data at rest security
Ask The Storage Channel Expert: Questions & Answers
EMAIL THIS

Data at rest security

Retired Expert - Randy Kerns EXPERT RESPONSE FROM: Retired Expert - Randy Kerns

Pose a Question
Other Storage Channel Categories
Meet all Storage Channel Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 15 January 2007
What security features should be included in a data at rest storage product?

>
EXPERT RESPONSE
Before considering what features should be in a data at rest storage product, a few more important items must be dealt with.

  • Is the storage removable? If so, there are more opportunities for problems. If the data is transported off site and physical control of the storage is turned over to an outside party, then some form of encryption may be required if the data is sensitive.

  • Is there physical security where storage system and data reside? If not, this needs to be resolved first.

  • Is the storage product equipped with prudent administrative controls? Are the number of people who have access to the data limited based on skill and role-based passwords, access controls lists, etc? Protecting data in a system is about controlling access. This happens primarily from the application standpoint because the data is meant to be used for processing.

Protecting data at rest that is not removable is about controlling access. Encrypting data at rest in an active storage system may not protect the data if the normal application access path is used -- the encryption may be useless without security around the application access. Also, encryption and other security measures come at the price of more operational expense such as managing keys and access controls. These require more staff, most product costs, and the barriers may significantly impede some normal operations.

Security is an overall system issue that starts with the quality of the personnel involved. It can't be looked at from a device perspective without addressing all of the other issues first.


Sound Off! -   Be the first to post a message to Sound Off!


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Storage Projects
Regulatory compliance requirements not met by storage services alone
Building trust with storage as a service
Benefits of VAR managed storage
Becoming a storage partner
Competitive analysis of new products
Why major vendors change value-added reseller (VAR) programs

Data Security Solutions
Defining data security vs. data protection
Data security services: Physical and logical data security strategies
Fibre Channel storage area network (SAN) security
Data-in-transit security and tracking services
Disaster recovery, data security and continuous data protection
Tape encryption options and security services

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsWebcastsWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts