Not Logged In

You could:

Log in
Register

research notes
  • Wikitips
  • Professional Alerts
  • Case Studies
  • How-to Notes
  • Community Questions
research meetings
  • Peer Incite Podcasts
  • Peer Incite Archive
Events
  • Enterprise Architect Summit 2008
    Oct 4-6, 2008
  • Peer Incite meeting - Topic: Best practice in tape backup and recovery
    Oct 7, 12:00-1:00 PM
  • Computerworld: Storage Networking World
    Oct 12-15, 2008
  • Usenix on the Road: Next Generation Storage Networking - 1/2 Day Lecture at the University of North Carolina
    Oct 16, 12:30-4:00 PM
  • Usenix on the Road: Next Generation Storage Networking - 1/2 Day Lecture at Virginia Tech
    Oct 21, 1:30-5:00 PM

Announcements
  • 10-07-08 Peer Incite: Best practice in tape backup and recovery
  • IBM's stealth XIV announcement
  • Welcome to Wikibon 2.0!
  • The IBM XIV Storage System Model A14
  • Storage Customers Seeing Green with Conserve IT
Home Profile Peers Wiki Groups Feedback


  • Article
  • Comments (0)
  • Page Protected
  • History
  • Vault
Storage security starts with a proper assessment
  • Currently n/a/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5
rate this
Last Update: Feb 16, 2008 | 08:25
Viewed 682 times | Community Rating: n/a
Originating Author: David Vellante

Originating Author: David Vellante

As with any risk mitigation initiative, storage security requires IT organizations begin by assessing the situation at hand. Making storage security a natural extension of storage pools and classification efforts will simplify the process.

Users need to identify information assets, their relative value, degree of exposure and liklihood of a breach. This can be done with a simple matrix that assesses exposure (loss potential) and probability of an event. It is advisable to enlist the stakeholders of the information in the process as they ultimately decide the value of data. However as is often the case with prioritization efforts, everyone believes his data is most important and should reside on the highest performance, most reliable systems. In the case of storage security the complicating issue often greater degrees of security will reduce flexibility, and business lines are typically willing to compromise security to preserve flexibility. These countervailing pressures should be considered and addressed in a relative manner in any assessment, in order to provide a clear picture to executive decision-makers.

In any event, the notion of a maximum acceptable loss (MAL) should be an outcome of the assessment. This threshold should guide storage managers and set the water mark for where discretionary decision-making can occur (i.e. if losses are kept below the MAL then it's up to the discretion of the IT organization to implement the right technologies and processes).

What follows are strategies to mitigate losses based on this assessment. This may involve:

  • Putting controls in place
  • Eliminating the risk
  • Transferring or sharing the risk
  • Accepting the risk (e.g. for low impact events)

All of this should be done with an understanding of the costs, potential losses and residual exposures that can exist for assets that cannot be protected fully due to costs or other factors.

Action Item: Storage security starts with a proper assessment of the assets being secured. IT should use a common framework that can be applied to cut through the politics of decision-making and, if necessary, used as a 'stick' to cajole stubborn lines-of-business who are willing to trade adequate security for flexibility.

Action Item:

Footnotes:

Storage_and_business_compliance,Storage_professional_alerts,Storage_security,Dvellante

categories
Storage and business compliance, Storage professional alerts, Storage security
Contributors

Dab4168

Comments (0)
Comments on 'Storage security starts with a proper assessment'
There are currently no comments. Be the first!
Post A Comment

You must be logged in to post a comment, please Sign in

Revision ID Author Timestamp Comment
13954 Dab4168 08 Feb 16 20:25:24 Removed category Author dvellante
9582 67.163.111.222 07 Jul 18 12:12:48
9559 Dvellante 07 Jul 17 15:09:46
9558 Dvellante 07 Jul 17 15:07:37
9557 Dvellante 07 Jul 17 15:07:00
9556 Dvellante 07 Jul 17 15:00:23
9555 Dvellante 07 Jul 17 14:59:22
9552 Dvellante 07 Jul 17 14:44:59
9551 Dvellante 07 Jul 17 14:42:11 initial post

Search:

news feed
  • Latest from Computerworld - Game economy grows with micropayments
  • eWeek - RSS Feeds - 5 Technology Businesses Poised to Boom in the Financial Crisis
  • InfoWorld RSS Feed - Microsoft lays out SQL Server roadmap
  • SearchStorage: News and trends in the storage industry - F5 Networks adds 10 GigE to ARX file virtualization product
  • Byte and Switch: - F5 Enhances File Virtualization Storage, Management
all »
blogs
  • Storagezilla - Sun batter NetApp in court
  • DrunkenData.com - Market Woes
  • StorageMojo - 3.5″ drives: the end is near
  • StorageRap - Mashup in blogland - will there be a future feeding franzy in 09?
  • Chuck's Blog - Virtual IT: A Frictionless World?
all »
companies
  • Dell
  • STEC inc
  • NetApp
  • LeftHand Networks
  • LSI
  • Hitachi
all »
Want a Wikibon
Peer Incite
newsletter?

Email: Privacy by Safe Subscribe
Storage Spectrum
Order Storage Spectrum
By Fred Moore
US & Canada Only!
Browse best practices . publish tips . access project tools . collaborate with peers . get help on RFP's . use privacy settings to control who sees your info . join a group and share experiences with colleagues . review case studies . read professional alerts
  • Cloud Computing
    Clustered storage, Storage services, WEB2.0
  • Companies
    3PAR, Compellent, Dell, EMC, EqualLogic, HP, Hitachi, IBM, LSI, LeftHand Networks, NetApp, STEC inc, Sun, XIV
  • Data Protection
    Backup and restore, Business compliance, CDP, Data deduplication, Storage disaster recovery, Storage security
  • Energy Efficiency
    Data deduplication, Green storage, MAID, Thin provisioning, Tiered storage, VMware, Virtual tape
  • Planning Design Implementation Management
    Backup and restore, Business compliance, Data classification, Green storage, Managing storage, ROI, SRM, Storage Design, Storage asset management, Storage capacity management, Storage capacity planning, Storage implementation, Storage management, Storage operations, Storage planning, Storage vendor management, Tiered storage
  • Storage networks
    Clustered storage, ISCSI, NAS, SAN, SRM, Storage consolidation, Tiered storage, VMware
  • Virtualization
    Clustered storage, Green storage, Storage consolidation, Storage virtualization, Thin provisioning, VMware, Virtual tape
© Wikibon 2008 About Wikibon l Contacts l Terms of Service l Disclaimers l Privacy l Help