Home > Storage Channel Tips > Regulatory Compliance Services > Defining data security vs. data protection
Storage Channel Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

REGULATORY COMPLIANCE SERVICES

Defining data security vs. data protection


Greg Schulz, Contributor
06.18.2007
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


When you hear the phrase data security, what comes to mind? Encryption, key management, locked doors, tamper-proof audit logs, firewalls, biometric card key access, passwords, logical, physical, privacy screen filters or secure erase and asset disposal? Answer 'yes' to any of these among others and you are on track with regard to data security. However, there is confusion between terms like data protection, which can mean protecting data through backup, snapshots and replication, and terms that infer data security from a logical or physical standpoint.

[TABLE]

Logical vs. physical data security

Logical security, particularly encryption, tends to get more coverage due to the increase in reported incidents of data being lost or stolen on laptop computers, disk drives or magnetic tapes. However, lost or stolen data can also be attributed to a lack of physical security and issues with logical security. Granted there are more external threats to data now than ever before, and you must secure data against threats beyond the confines of a customer's business to meet privacy and regulatory compliance requirements. Yet when speaking with IT organizations of all sizes, a common concern is internal threats, in addition to external threats.

Let's review some techniques and technologies to address various security threat risks.

Physical security services may include the following:

  • Physical card and ID, if not biometric access card, for secure facilities
  • Security and safe disposition of storage media and assets
  • Asset and media audits on site and off site
  • RFID-enabled volume labels for removable magnetic tape and disks
  • GPS-enabled tracking transportation or shipping cases for removable media
  • <

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Data Security Solutions
    Data security services: Physical and logical data security strategies
    Fibre Channel storage area network (SAN) security
    Data-in-transit security and tracking services
    Disaster recovery, data security and continuous data protection
    Tape encryption options and security services
    Data at rest security

    Data Center and Server Room Storage
    Fusion-io looks to replace SAN with SSD; JCPenney cuts IT energy use (news roundup)
    Green storage options for data centers
    Solid-state drives a good fit for critical transactions
    TCP/IP offload engine (TOE) cards
    Server room design services tutorial
    Data center infrastructure management: Power and cooling tips
    Data storage hardware spending declines, CIOs show caution
    Server room design and data storage facility planning guide

    Storage Service Provider Concerns
    Channel Spin: Analysis for storage solution providers
    NetApp/Data Domain deal: The impact on VARs
    Positioning storage services to take advantage of stimulus package
    Eight steps to a low-cost IT training program
    Storage RFP: Selection process mistakes and best practices
    Storage services messaging: 6 paths to a healthy 2009
    VMware ESX essentials: Fibre Channel and iSCSI
    Storage trends 2009: Strategies for solution providers
    VMware ESX essentials: Virtual Machine File System
    Top 10 storage tips for solution providers from 2008

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary


    li>Secure digital shredding of deleted data with appropriate audit controls

  • Video surveillance of IT assets and equipment and management consoles
  • Physical transportation of removable media (disks, tapes, CDs) and printouts
  • Monitoring of IT equipment, including power, cooling and ventilation
  • Locked doors to equipment rooms and secure cabinets and network ports
  • Background checks on employees and contractors who handle data and media
  • Usage or disablement of portable media including PDA and USB thumb drives
  • Asset tracking of portable devices and personal or visiting devices
  • Limits or restrictions on photo or camera usage in and around data centers
  • Low-key facilities absent of large signs advertising a data center's location
  • Closed window blinds, especially when using backup power during a power outage
  • Protected (hardened) facility against fire, flood, tornado and other events
  • Logical security services may include the following:

  • Usernames and passwords along with rights management
  • Virtual private networks (VPNs)
  • User credential authentication and individual rights authorization
  • Logical storage partitions and logical or virtual storage systems
  • Audit trails and logs of who accessed what, when and from where
  • LUN and volume mapping and masking, and SAN port and device zoning
  • SAN segmentation and logical isolation (logical SANs)
  • Encryption of data at rest (on disk or tape) or in flight (transmitted over network)
  • Encryption key and digital rights management
  • Secure servers, file systems, storage, network devices and management tools
  • [TABLE]

    [TABLE][TABLE]

    Rate this Tip
    To rate tips, you must be a member of SearchStorageChannel.com.
    Register now to start rating these tips. Log in if you are already a member.




    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

    HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts