Home > Storage Channel All-in-One Guides > Data Security Services Guide > Data Security Solutions > Tape encryption options and security services
All-in-One Guides: Data Security Services Guide:
EMAIL THIS
 START   TECHNOLOGY OVERVIEW   ISSUES AND TRENDS   PLANNING AND TESTING   OFFSITE STORAGE SECURITY   DATA SECURITY SOLUTIONS   
Data Security Solutions

<< PREVIOUS | NEXT >>: Data-in-transit security and tracking services
 TIPS & NEWSLETTERS TOPICS 

STORAGE SERVICE PROVIDER CONCERNS

Tape encryption options and security services


Greg Schulz, Contributor
02.14.2007
Rating: --- (out of 5)


Storage Channel Update
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


The demise of magnetic tape has been speculated and greatly exaggerated for years. The reality is that tape remains a viable data storage medium for different applications and environments. While network and disk-to-disk backup and archive solutions continue to proliferate, at least for the foreseeable future, there will remain some role for magnetic tape; it will be necessary for long-term data preservation and archiving to meet regulatory compliance or federal guidelines.,

The truth about tape
Despite many claims that tape is dead, it can be a good complementary technology to disk-to-disk data protection. Data protection expert Greg Schulz writes more on tape realities.

Hardly a week goes by without some news of a lost or stolen laptop computer, magnetic tape, disk or USB thumb drive, or a data security breach. No matter how few tapes are actually stolen, the perception is that tape data is being lost and measures must be taken to protect data in transport or storage.

While many advocate moving away from tape using disk-based backup, network-based backup or electronic vaulting for archive, without introducing some form of encryption and enhanced security they're simply moving the problem from one medium to another. As a channel professional there are many things that you can do to help improve the security of data at rest and in transit for your clients. For example work with your clients to introduce encryption of data at rest on disk and tape, and data being transferred or removed from your premises.,

Options for encrypting tape data include host-based software, including applications, databases, and third-party encryption tools, network-based encryption appliances along with tape library and tape-drive encryption. Where to implement encryption will depend on yours and your clients' preferences (i.e. host software vs. appliance vs. drive-level encryption).

IBM aims tape library at midsized customers
IBM is adding to its TS line of storage solutions with a tape library product that offers encryption capabilities, aimed at midsized companies. Find out how and where you may be able to implement it in customer shops.

A benefit of host software encryption is that any data leaving a server assuming the software is configured to do so will be encrypted. The down side is that extra CPU cycles will be consumed to handle encryption activity. Appliance-based solutions, depending on implementation, could introduce extra latency. However, they can also offload host processors from performing encryption and being deployable to where and how necessary on a tactical and strategic basis. Drive-based encryption offloads host processors and eliminates appliances, but a concern may be its impact on tape-drive performance and key management.

Central to any encryption and data security strategy is encryption key management. Various approaches to key management are being offered by vendors to address vendor lock-in concerns and interoperability. In addition to using different keys to encrypt various tapes and data, part of a security strategy involves controlling who has access to the tapes and keys. Given that tapes are still part of some organizations disaster recovery and business continuance plans, key management must be part of a DR plan to facilitate timely data recovery.

An approach used by some involves listing or indicating which keys are required for which tapes. Note that this is not the actual key to unlock the data, but rather an indicator of which key to use, similar to a stamped indicator code you may find on your office or household key. If you have a tape and are authenticated and authorized to use the tape and have the keys, you know which key to use for which tape. A handy analogy is that of a key with a stamped code on it and a list of which locks are unlocked by that specific key on a key chain.

CA offers mainframe tape encryption
CA offers mainframe tape encryption with its BrightStor Tape Encryption appliance. Get more information to see if this product is suitable for your customers.

Many backup software vendors provide some form of encryption as do third-party providers BitArmor, RSA (now EMC), PGP, GFI and Innovation (IDP) among others. Appliances are available from vendors including Decru (Network Appliance) and NeoScale, which also provides key management for other vendors. Tape drive and library encryption is offered depending on specific models by IBM, Sun and Spectra Logic, among others. Look for encryption solutions that can work with open key management solutions, cross vendor interoperability and provide layers of protection and management granularity. Also look for vendors that have extensive partnerships with other technology providers to coexist with your client's current environment. Other items to consider include solution transparency, performance, reliability and certifications.,

Some items to look at and consider with regard to tape encryption include:

  • Tape media and drive agnostic and interoperability;
  • Ability to save and transport or replicate keys to a DR or alternative site;
  • Assignable descriptors or monikers to identify which tapes require which key;
  • Ability to assign different keys to separate tapes or groups of tapes;
  • 128 and 256-bit Advanced Encryption Standard (AES) capabilities;
  • Tamper-proof access and audit trail logs;
  • Secure shredding of encrypted data;
  • Flexible and easy to use key creation, assignment and escrow;
  • Coexistence with other key management and encryption products;
  • High-performance encryption to avoid bottlenecks.
Tape backup resources 
Get more tape backup resources in this SearchStorageChannel.com topics section.

If your clients are currently not encrypting tapes, ask them why and if the reason is fear of losing encryption keys, then have a discussion about key management. If clients are not encrypting data because they think no data is at risk, ask if they know for sure what data is on any given tape, including PCI, social security or other unknown data. Another common reason people may not encrypt their tapes or data is the perception that the tapes are safe in the hands of their own employees and no outside services are involved in tape and data handling.

Whether you or your clients are moving away from magnetic tape to optical or magnetic disk-based storage for data storage and preservation, given applicable threat risks, securing data has taken on new and visible importance. Look into encryption and key management solutions as a value-add service for your clients and make sure tapes are encrypted, especially if you do not know what is on the tape. In addition, look into encrypting data that is being stored on disk drives, removable media, laptops, USB thumb drives or data being sent over networks.

About the author: Greg Schulz is founder and senior analyst of the independent storage analyst firm the StorageIO group and author of the bookResilient Storage Networks, (Elsevier).


Rate this Tip
To rate tips, you must be a member of SearchStorageChannel.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


<< PREVIOUS | NEXT >>: Data-in-transit security and tracking services
VIEW ALL IN THIS CATEGORY

RELATED CONTENT
Storage Service Provider Concerns
Beating out storage manufacturers for installation service contracts
Storage certification and training: Big gaping holes
Our top five storage tips -- so far
Top five storage channel tips of 2007
How to improve data backup time
Disk libraries: Picking the right one for data backup
Email classification, search and discovery for FRCP litigation
Defining data security vs. data protection
Data security services: Physical and logical data security strategies
Storage virtualization technology for the SMB

Tape Backup
What's the role of tape backup in disaster recovery?
How does a customer's data backup method impact capacity planning?
Is online backup a good alternative for SMBs?
Choosing a backup tape drive: Fastest isn't necessarily best
IBM answers VAR requests for midsized company tape storage
For tape storage, "not dead yet" is too pessimistic a rating
Tape backup trends and technologies
The truth about tape

Data Security Solutions
Defining data security vs. data protection
Data security services: Physical and logical data security strategies
Fibre Channel storage area network (SAN) security
Data-in-transit security and tracking services
Disaster recovery, data security and continuous data protection
Data at rest security

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts