Not Logged In

You could:

Log in
Register

research notes
  • Wikitips
  • Professional Alerts
  • Case Studies
  • How-to Notes
  • Community Questions
research meetings
  • Peer Incite Podcasts
  • Peer Incite Archive
Events
  • Enterprise Architect Summit 2008
    Oct 4-6, 2008
  • Peer Incite meeting - Topic: Best practice in tape backup and recovery
    Oct 7, 12:00-1:00 PM
  • Computerworld: Storage Networking World
    Oct 12-15, 2008
  • Usenix on the Road: Next Generation Storage Networking - 1/2 Day Lecture at the University of North Carolina
    Oct 16, 12:30-4:00 PM
  • Usenix on the Road: Next Generation Storage Networking - 1/2 Day Lecture at Virginia Tech
    Oct 21, 1:30-5:00 PM

Announcements
  • 10-07-08 Peer Incite: Best practice in tape backup and recovery
  • IBM's stealth XIV announcement
  • Welcome to Wikibon 2.0!
  • The IBM XIV Storage System Model A14
  • Storage Customers Seeing Green with Conserve IT
Home Profile Peers Wiki Groups Feedback


  • Article
  • Comments (0)
  • Page Protected
  • History
  • Vault
Implementing storage network security
  • Currently n/a/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5
rate this
Last Update: Feb 20, 2008 | 11:04
Viewed 2993 times | Community Rating: n/a
Originating Author: Janet Engle

Originating Author: Janet Engle

In the early days of the computer industry, storage systems were physically large and resided within the confines of a controlled data center environment. Storage systems have evolved into lightweight devices and are easily accessible over corporate networks, making them more vulnerable to security breaches. Fueled by the growing costs of recovering from intrusions, public concerns over privacy and identity theft, and increased government regulations, businesses are spending more time and money to develop or improve storage network security systems.

Data storage security is regulated by various state, federal, local and industrial ordinances. In many cases, failure to provide adequate security can result in legal sanctions against the company or executives.

Information security ordinances include:

Health Insurance Portability and Accountability Act (HIPAA)

  • HIPAA regulates how Protected Health Information (PHI) can be used and to whom it may be disclosed. PHI includes health status, health care and health-related payment history that can be linked to an individual. HIPAA requires that companies make a reasonable effort to disclose PHI only to authorized recipients.

Gramm-Leach-Bliley Act (GLBA)

  • GLBA requires that financial institutions have a written plan for data security and perform a risk analysis on their current practices. Institutions are required to protect consumers’ personal information.

California Information Practice Act (SB 1386)

  • The California Information Practice Act requires businesses to notify California residents – whether they are employees, customers or clients – when there has been a verified or suspected data breach involving their personal information.


Contents

  • 1 Storage network security capabilities
  • 2 Specific operational goals of storage network security
  • 3 Storage network security implementation risks
  • 4 Storage network security initiative
    • 4.1 Expectations (Out-of-scope)
    • 4.2 Analyze phase
      • 4.2.1 Acceptance test considerations
      • 4.2.2 Key analysis milestones
    • 4.3 Design phase
      • 4.3.1 Acceptance test considerations
      • 4.3.2 Key design milestones
    • 4.4 Deployment phase
      • 4.4.1 Acceptance test considerations
      • 4.4.2 Key deployment milestones
  • 5 Initiative summary

Storage network security capabilities

Storage network security is the protection of digital information as it is being stored (“at rest”) or transferred across local or public networks (“in motion”). Storage network security involves all procedures that limit the unauthorized access of data, from turning monitors away from public areas to using advanced encryption protocols.

Security for shared network storage devices typically address vulnerabilities by providing some combination of the following: 1) authentication and auditing capabilities which track who made changes to which data and when; 2) physical security, ranging from locked doors to bank-like procedures measuring the weight and metal content of people entering and leaving a site and 3) Encrypting data in arrays or tape systems which use keys to render data unreadable to non-authorized devices.

Specific operational goals of storage network security

The cost of implementing network security averages about 6% of a business's IT budget. For the standard WikiBon business model, this equals approximately $2.4 million. Yearly maintenance costs to keep security devices and software updated average 1.5% of total IT spending, or $0.6 million for the standard WikiBon business model.

Applying this to storage network security would indicate approximately 5-10% of the storage budget should be allocated to storage network security annually. This would equate to as high as $0.5M using the standard WikiBon business model.

Although many companies underfund information security efforts, investing in them can have a significant ROI. In 2006, companies spent an average of almost $5 million on security because of storage network breaches. The average cost to recover a single lost record is $140.

Security breaches that are the result of noncompliance can result in hefty fines. On 1/26/2006, nearly a year after 163,000 records were breached, ChoicePoint of Alpharetta, GA settled with the Federal Trade Commission (FTC) for $15 million in penalties.

Depending on the type of and sensitivity of the information being stored, data security efforts may be geared toward a combination of several goals:

  • To protect against data theft.
  • To limit the possibility of legal penalties and public backlash because of unauthorized access to data.
  • To prevent unauthorized changes to data records, whether malicious or accidental.
  • To establish the authenticity of information records and transactions.
  • To increase business activity uptime.
  • To comply with industry-specific regulations.

In addition, if approached properly, storage network security can feed corporate compliance systems and save on reporting costs.

Storage network security implementation risks

There are several risks that can threaten the successful implementation of a storage network security system, including:

  • Encryption. Encryption involves tradeoffs. For example, if encryption occurs too early in the process it can negatively impact data compression rates. If encryption goes wrong (for example if keys are corrupted or lost) data becomes unreadable.
  • Availability impacts. Storage network security involves substantial changes to management software and processes which can negatively impact application availability during the adoption phase.
  • Attitude, culture and mindset. Adding unfamiliar or more complicated protocols to access data may frustrate programmers and employees, negatively impacting morale and productivity.
  • Storage network security standards are evolving somewhat rapidly, especially outside of traditional mainframe environments. What's implemented today may be outdated in the near-to-mid term.
  • Applying storage security to remote disaster recovery systems complicates an already complicated and expensive process.

In addition, using outside contractors to develop, deploy or audit a security system creates more access points where insider, close-in and distribution attacks can occur. Screening contractors and using reputable companies can help reduce this risk.

Storage network security initiative

Broadly, there are three types of storage network security safeguards:

Administrative

Administrative security safeguards include written policies and procedures about who is authorized to access data, protection plans, contingency plans in case of data emergencies and security breaches, and network security training. Administrative strategies attempt to reduce malicious and nonmalicious insider attacks.

Physical

Physical security measures include controlling physical access to data records. This includes removing workstations from high traffic areas, disposing of retired equipment in a way that doesn’t jeopardize data, controlling where data is physically stored, and monitoring the use of hardware and software inside and outside of the company’s facilities.

It is likely that most security breaches can be prevented by increased physical safeguards. In a 2006 study, The Poneman Institute found that 49% of security incidents were the result of lost portable devices. Another 26% were the result of lost electronic backup devices.

Physical strategies are generally focused on protecting against insider and close-in attacks.

Technological

Technological safeguards are means to prevent data communications from being accessed by anyone other than the intended recipient and protecting all devices involved in the storage network from unauthorized access. Technological safeguards include password systems, external authentication, two- or three-way handshakes, centralized logging and digital signatures.

Technological strategies help protect against active, passive and distribution attacks.

Depending on degree of risk, complexity, cost and skill sets, these approaches will be implemented to varying degrees through the analyze, design and deploy phases of a storage network security project.

Expectations (Out-of-scope)

The following items are necessary and should be in place for a successful storage network security implementation:

  • An overall IT and network security risk assessment study has been completed including threat probabilities and overall business impacts. This will set a context and basis to develop a credible storage network security plan.
  • Overall IT security objectives and advised spending levels and budgets are in place so that a storage security plan can be developed in context.
  • Requirements for compliance reporting have been established such that the storage network security component can feed the overall reporting system.

Analyze phase

Acceptance test considerations

The analysis phase is complete when the current storage network security system and the current and future security needs have been identified, documented and the following items have been agreed with the overall IT security group ('Security Czar'):

  • The risks have been identified and quantified including cost of exposure down to the storage network level.
  • Analysis and strawman solution for each of the areas of risk has been put forth (e.g. audit, authentication, physical, encryption).
  • High level gap analysis identifying weaknesses in current architecture, auditing and authentication.
  • Cost of the project has been generally estimated and agreed.

Key analysis milestones

  1. Candidate data identified and potential threats classified
  2. Security priorities assessed
  3. Security features gap analysis conducted between current system and desired state
    • Are they up-to-date?
    • Do they protect the data at every point from which it can be accessed?
    • Has it adequately protected the network against previous attacks?
  4. Perimeter of storage network determined
    • Does the data flow to or from remote locations?
    • Do you exchange information with other companies?
  5. Applicable regulations researched and documented
    • Does the current security system meet or exceed industry and government requirements
  6. First pass (strawman) design proposed
    • Complete cost estimates as a baseline for design phase
  7. Recommendation finalized as to how to proceed
    • Order of storage network security measures to be implemented identified

Design phase

Acceptance test considerations

The design phase is complete when a plan for meeting the company’s storage security needs has been developed and accepted by the IT security decision-making group.

Key design milestones

  1. Attack points determined for potential data threats
    • Penetration tests that simulate attacks on the storage network can help locate vulnerabilities
  2. Network security requirements prioritized
    • Develop functional rollout plan accordingly for storage network components
  3. Physical threat policies developed
  4. Intrusion prevention system (IPS) and Intrusion detection system (IDS) architected within the storage network
    • An IDS constantly monitors the storage network, looking for activity that indicates a data security breach
    • If a suspicious pattern in noticed, the IPS immediately shuts down all data flow to the suspect part of the storage network and alerts appropriate individuals
  5. Authentication and auditing software researched and selected.
    • Authentication and auditing software identifies applications trying to access data and determines if the access should be allowed or denied
  6. Secure backup and remote data recovery measures developed
  7. Reporting procedure developed
    • Emphasize a reporting procedure so employees can inform appropriate IT professionals if they are unable to access necessary data or services
  8. Process to feed compliance reporting system designed
  9. Testing procedures for deploy phase designed

Deployment phase

Acceptance test considerations

The implementation phase is complete when the new storage security system is built, tested and brought into service. The system should be evaluated regularly by independent security auditors throughout its lifespan.

Key deployment milestones

  1. Highest priority components of storage network strategy implemented
    • Implement appropriate auditing, authentication, physical security and encryption strategies as specified in design phase.
  2. Testing completed
    • Check of compliance with test scripts recommended in design phase
    • Perform tests
    • Verify system behaves as expected
  3. Training completed
    • Develop courseware
    • Develop rules, regulations and clear penalties for violations
    • 100% of relevant professionals trained, certified and informed of changes in policies
  4. Change management processes and procedures established
  5. Follow-up penetration tests performed
    • Comparison protocols defined and implemented - regularly comparing two or more sets of the same data helps reveal unauthorized modification or destruction of information and ensure the integrity of the network
    • Regularly scan, test and audit storage network activity
    • Record all user activity and review on a regular basis
  6. Security rules and procedures updated

Initiative summary

Implementing storage network security is a journey that should be taken in steps starting with the highest risk data and the strategies that will give the best return on investment. Frequently auditing and authentication are good starting points and will provide meaningful impacts. Physical security can often provide excellent benefits and is generally straightforward. Encryption, while potentially powerful and often critical, carries the greatest degrees of complexity and risk.

categories
How-To notes, Storage security
Contributors

Dab4168

Mrgood

Dvellante

Comments (0)
Comments on 'Implementing storage network security'
There are currently no comments. Be the first!
Post A Comment

You must be logged in to post a comment, please Sign in

Revision ID Author Timestamp Comment
14095 Dab4168 08 Feb 20 11:04:28 Removed category: Level 1
9513 66.202.41.205 07 Jul 12 15:57:51
9512 66.202.41.205 07 Jul 12 15:56:49
7415 Dab4168 07 Mar 08 17:47:53 Re-categorization
4663 Mrgood 07 Jan 04 13:38:13
4615 Dvellante 07 Jan 03 23:04:13
4567 Dvellante 07 Jan 03 22:13:35
4566 Dvellante 07 Jan 03 22:13:22
3216 Dvellante 06 Dec 06 22:47:35
3147 Dab4168 06 Dec 06 18:08:26 /* Specific operational goals of storage network security */ misc
3138 Dvellante 06 Dec 06 17:43:24 [[Storage network security]] moved to [[Implementing storage network security]]: verbize
3071 Mrgood 06 Dec 06 10:41:18
3068 Mrgood 06 Dec 06 10:39:03
3017 Dvellante 06 Dec 05 22:21:19 /* Initiative summary */
3016 Dvellante 06 Dec 05 22:20:18 /* Key analysis milestones */
3015 Dvellante 06 Dec 05 22:19:35 /* Key design milestones */
3014 Dvellante 06 Dec 05 22:18:37 /* Key deployment milestones */
3013 Dvellante 06 Dec 05 22:17:18 /* Key analysis milestones */
3012 Dvellante 06 Dec 05 22:16:54 /* Key analysis milestones */
3011 Dvellante 06 Dec 05 22:15:47 /* Acceptance test considerations */
3010 Dvellante 06 Dec 05 22:14:19 /* Expectations (Out-of-scope) */
3009 Dvellante 06 Dec 05 22:12:30 /* Storage network security implementation risks */
3008 Dvellante 06 Dec 05 22:11:11 /* Specific operational goals of storage network security */
3007 68.189.241.40 06 Dec 05 22:07:36
3006 75.19.85.38 06 Dec 05 16:16:11
3005 Dab4168 06 Dec 05 15:56:17 /* Storage network security implementation risks */ grammer
3004 Dvellante 06 Dec 05 15:49:42 /* Storage network security initiative */
3003 Dvellante 06 Dec 05 15:46:57 /* Storage network security initiative */
3002 Dvellante 06 Dec 05 15:44:16 /* Key deployment milestones */
3001 Dvellante 06 Dec 05 15:40:51 /* Key deployment milestones */
3000 Dvellante 06 Dec 05 15:35:15 /* Key deployment milestones */
2999 Dvellante 06 Dec 05 15:32:48 /* Key design milestones */
2998 Dvellante 06 Dec 05 15:32:01 /* Key design milestones */
2997 Dvellante 06 Dec 05 15:31:24 /* Key design milestones */
2996 Dvellante 06 Dec 05 15:23:54 /* Key analysis milestones */
2995 Dvellante 06 Dec 05 15:20:09 /* Key analysis milestones */
2994 Dvellante 06 Dec 05 15:19:00 /* Key analysis milestones */
2993 Dvellante 06 Dec 05 15:13:33 /* Key analysis milestones */
2992 Dvellante 06 Dec 05 15:12:29 /* Expectations (Out-of-scope) */
2991 Dvellante 06 Dec 05 14:59:33 /* Expectations (Out-of-scope) */
2990 Dvellante 06 Dec 05 14:58:33 /* Types of storage network security safeguards */
2989 Dvellante 06 Dec 05 14:58:04 /* Storage network security initiative */
2988 Dvellante 06 Dec 05 14:44:34 /* Storage network security implementation risks */
2987 Dvellante 06 Dec 05 14:31:30 /* Specific operational goals of storage network security */
2986 Dvellante 06 Dec 05 14:30:29 /* Storage network security benchmarks */
2985 Dvellante 06 Dec 05 14:29:50 /* Storage network security initiative */
2984 Dvellante 06 Dec 05 14:29:25 /* Types of storage network security safeguards */
2983 Dvellante 06 Dec 05 14:27:03 /* Specific operational goals of storage network security */
2982 Dvellante 06 Dec 05 14:24:14 /* Storage network security costs */
2981 Dvellante 06 Dec 05 14:23:56 /* Specific goals of storage network security */
2980 Dvellante 06 Dec 05 14:22:11
2979 Dvellante 06 Dec 05 14:21:16
2978 Dvellante 06 Dec 05 14:21:04
2977 Dvellante 06 Dec 05 14:19:50
2976 Dvellante 06 Dec 05 14:18:26 /* Types of data in storage networks */
2975 Dvellante 06 Dec 05 14:17:54
2974 Dvellante 06 Dec 05 13:21:36 /* Storage network security initiative */
2973 Dvellante 06 Dec 05 13:14:21 /* Storage network security initiative */
2972 Dvellante 06 Dec 05 13:11:55 /* Storage network security initiative */
2971 Dvellante 06 Dec 05 13:06:44 /* Storage network security initiative */
2970 Dvellante 06 Dec 05 13:03:08 /* Storage network security initiative */
2969 Dvellante 06 Dec 05 13:02:37 /* Storage network security initiative */
2968 Dvellante 06 Dec 05 13:01:38 /* Storage network security initiative */
2967 Dvellante 06 Dec 05 12:34:30 /* Storage network security costs */
2966 Omengle 06 Dec 05 12:03:43 /* Storage network security implementation procedures */
2965 66.202.41.205 06 Dec 05 08:49:21
2964 Omengle 06 Dec 05 07:52:03 /* Storage network security implementation procedures */
2963 Omengle 06 Dec 05 07:50:54 /* Storage network security implementation procedures */
2962 Omengle 06 Dec 05 07:47:26 /* Storage network security implementation procedures */
2961 Omengle 06 Dec 05 07:44:40 /* Types of data in storage networks */
2960 Omengle 06 Dec 04 21:10:17 /* Storage network security implementation procedures */
2959 Omengle 06 Dec 04 21:01:34 /* Storage network security implementation procedures */
2958 Omengle 06 Dec 04 20:56:40 /* Storage network security costs */
2957 Omengle 06 Dec 04 20:54:06 /* Storage network security implementation procedures */
2956 Omengle 06 Dec 04 20:52:38 /* Storage network security implementation procedures */
2955 Omengle 06 Dec 04 20:52:08 /* Storage network security implementation procedures */
2954 Omengle 06 Dec 04 20:50:51 /* Storage network security implementation procedures */
2953 Omengle 06 Dec 04 20:50:02 /* Storage network security implementation procedures */
2952 Omengle 06 Dec 04 20:47:42 /* Storage network security implementation procedures */
2951 Omengle 06 Dec 04 20:38:15 /* Storage network security implementation procedures */
2950 Omengle 06 Dec 04 20:23:56 /* Storage network security costs */
2949 Omengle 06 Dec 04 20:21:30 /* Storage network security implementation procedures */
2948 Omengle 06 Dec 04 20:14:43
2947 Omengle 06 Dec 04 20:12:15
2946 Omengle 06 Dec 04 20:04:06 /* Storage network security implementation procedures */
2945 Omengle 06 Dec 04 19:29:31 /* Storage network security implementation procedures */
2944 Omengle 06 Dec 04 19:25:16 /* Storage network security implementation procedures */
2931 66.202.41.205 06 Dec 04 08:30:38
2926 216.9.250.6 06 Dec 01 22:53:36 /* Storage network security implementation risks */
2925 216.9.250.6 06 Dec 01 22:52:01 /* Storage network security implementation risks */
2924 216.9.250.6 06 Dec 01 22:46:59 /* Specific goals of storage network security */
2923 Omengle 06 Dec 01 21:40:05 /* The price of a security breach */
2922 Omengle 06 Dec 01 21:34:17 /* The price of a security breach */
2921 Omengle 06 Dec 01 21:33:30 /* Types of data in storage networks */
2920 Omengle 06 Dec 01 21:21:23 /* Storage network security implementation risks */
2919 Omengle 06 Dec 01 21:13:20 /* Specific goals of storage network security */
2918 Omengle 06 Dec 01 21:13:07 /* Types of storage network security safeguards */
2917 Omengle 06 Dec 01 21:12:53 /* Types of storage network security safeguards */
2916 Omengle 06 Dec 01 21:12:29 /* Storage network security implementation procedures */
2915 Omengle 06 Dec 01 21:12:02 /* Storage network security implementation procedures */

Search:

news feed
  • Latest from Computerworld - Game economy grows with micropayments
  • eWeek - RSS Feeds - 5 Technology Businesses Poised to Boom in the Financial Crisis
  • InfoWorld RSS Feed - Microsoft lays out SQL Server roadmap
  • SearchStorage: News and trends in the storage industry - F5 Networks adds 10 GigE to ARX file virtualization product
  • Byte and Switch: - F5 Enhances File Virtualization Storage, Management
all »
blogs
  • Storagezilla - Sun batter NetApp in court
  • DrunkenData.com - Market Woes
  • StorageMojo - 3.5″ drives: the end is near
  • StorageRap - Mashup in blogland - will there be a future feeding franzy in 09?
  • Chuck's Blog - Virtual IT: A Frictionless World?
all »
companies
  • Hitachi
  • 3PAR
  • Compellent
  • STEC inc
  • HP
  • NetApp
all »
Want a Wikibon
Peer Incite
newsletter?

Email: Privacy by Safe Subscribe
Storage Spectrum
Order Storage Spectrum
By Fred Moore
US & Canada Only!
Browse best practices . publish tips . access project tools . collaborate with peers . get help on RFP's . use privacy settings to control who sees your info . join a group and share experiences with colleagues . review case studies . read professional alerts
  • Cloud Computing
    Clustered storage, Storage services, WEB2.0
  • Companies
    3PAR, Compellent, Dell, EMC, EqualLogic, HP, Hitachi, IBM, LSI, LeftHand Networks, NetApp, STEC inc, Sun, XIV
  • Data Protection
    Backup and restore, Business compliance, CDP, Data deduplication, Storage disaster recovery, Storage security
  • Energy Efficiency
    Data deduplication, Green storage, MAID, Thin provisioning, Tiered storage, VMware, Virtual tape
  • Planning Design Implementation Management
    Backup and restore, Business compliance, Data classification, Green storage, Managing storage, ROI, SRM, Storage Design, Storage asset management, Storage capacity management, Storage capacity planning, Storage implementation, Storage management, Storage operations, Storage planning, Storage vendor management, Tiered storage
  • Storage networks
    Clustered storage, ISCSI, NAS, SAN, SRM, Storage consolidation, Tiered storage, VMware
  • Virtualization
    Clustered storage, Green storage, Storage consolidation, Storage virtualization, Thin provisioning, VMware, Virtual tape
© Wikibon 2008 About Wikibon l Contacts l Terms of Service l Disclaimers l Privacy l Help