Opinion
GlassHouse Technologies Outlines Gameplan for Storage Security
By James Damoulakis Wed, Jul 15, 2009James Damoulakis is Chief Technology Officer at GlassHouse Technologies, an IT infrastructure consulting and services firm.
How much progress is really being made in securing storage? For several years now, pundits have sounded the alarm about a range of security risks associated with storage. That includes everything from a lack of fundamental network security practices for SANs to the ever-familiar problems associated with handling off-site media. Regarding the latter, hardly a week goes by that some organization isn’t reporting the loss or theft of laptops or tapes containing confidential data. Yet, besides those corporate victims in the spotlight that have been forced to make improvements, it seems that the state of storage security has been advancing very slowly.
Furthermore, many so-called storage security initiatives should be more accurately labeled as off-site tape security initiatives. In other words, the focus isn’t on a strategic approach to securing the overall storage infrastructure, but on the pain point du jour — in this case, the desire to avoid being the next organization to make headlines in for the wrong reason. Certainly, the desire to close this particular security hole is understandable, but without an overall game plan, there is a strong likelihood that efforts will be duplicated and other risks overlooked.
A study from the Identity Theft Resource Center found a 47 percent increase in data breaches in 2008 compared with 2007. Of these breaches, 20.7 percent involved ‘data on the move’— on laptops or tapes, for example. However, twice as many incidents (41 percent) occurred through a combination of hacking, insider theft and subcontractor breaches.
Yet even the goal of securing off-site media hasn’t been successfully addressed. Consider, for example, the lack of wide-scale adoption of encryption. Only 2.4 percent of the lost media in the above study was encrypted. Why is that? In the case of tape, it’s not because of a lack of awareness or misunderstanding the problem — that’s painfully obvious. Nor is it because of a lack of technology available to address the problem. Encryption products for every level can be obtained from mainstream vendors: tape drive, tape library, SAN switch, SAN or LAN appliance and host software.
It’s easy to point to the challenges of key management as the primary roadblock to more widespread adoption of media encryption, and this is certainly a contributing cause. However, the problems of key management point to a larger issue: the lack of a comprehensive security strategy that truly encompasses storage. As long as storage sits at the periphery of organizations’ security focus, there will continue to be risks, and obstacles to addressing those risks.
What’s required is understanding that different entities within an enterprise access, manage, control and own responsibility for data. An effective strategy considers the security needs of all constituents.
A strategic approach to storage security not only would weigh additional risks beyond things like off-site media encryption, but would also consider identifying which data needs to be encrypted and at what level. Perhaps if data is encrypted at the application level to protect against unauthorized access, it might not need to be re-encrypted at the tape level. If a centralized key-management function, with associated policies and processes, were instituted to manage all data security access, the prospect of off-site tape encryption wouldn’t be as daunting.
Given the current economic reality, it’s improbable that many organizations will undertake this type of program in the near future. However, it’s important to begin to bridge the gap between storage and security and build a rational framework on which to incrementally improve. Otherwise, the breach tally is certain to climb even higher in 2009.
Channelworld.in Opinion
-
Spotlight: Die, Desktop, Die: Enter Virtualization
DV is cheap for licensing and hardware, but unless all users are similarly engaged, lack of customization can dampen productivity.
IT Relief Will Lag Economic Recovery
I expect that hiring will be biased toward those who are currently working. The assumption is that people with jobs must be more talented.
-
Linux Desktop Turns 10; World Yawns
A lack of marketing, an unfriendly environment, and infighting among the Open Source faithful have hurt Linux desktop adoption.
Spotlight: Is Open Source ERP Right For You?
In late 2007, CIO surveyed 400 IT leaders about their ERP systems. Despite innovation, integration and cost issues, they said they remained committed to on-premise, traditional ERP systems. Just 9 percent reported using an alternative ERP model.
-
Intel Eyes More Important Threats
Intel cannot afford to let AMD go out of business. It needs them for the competition to stay “paranoid” enough to make industry-leading chips.
Fending Off The Business Case Blues
Business cases help clarify and quantify project requirements and contingency plans, which enhance the chances that the project will be a success.
-
Editorial: Attrition, Competition & A Reviving Economy
As the economy perks up and business begins to look better, the good and the not so good (sometimes referred to as bad) things will come hand in hand.
Is Microsoft’s SharePoint at Risk?
An IDC report found that 54.2% of companies using SharePoint team sites find managing content on the sites a tremendous challenge.
-
Gaming Expertise in the Workplace
Games can help get consumers interested in products without making them feel as if they are getting a sales pitch and can be adopted for feedback.
IT Plus Users Equals Benefits
IT and users should explore how technology could impact users, the potential for competitive advantage, and compatibility with existing systems.
Related Contents in ChannelWorld.in
-
open/close Interviews
-
open/close Features
-
open/close FastTrack
-
open/close CaseFiles
-
open/close Partner Hotline


Mandeep Gupta, Country Manager – Channel Business, Emerson Network Power India
,
Anil Pant, VP, Channel Sales, Sify
Subhodeep Bhattacharya, Country Manager, India, ProCurve Networking by HP
Debraj Dam, Sales Head – Strategic Accounts, DIGILINK