Do we really care about storage security?
Computerworld -
How many stories about lost backup media will it take before we all finally get serious about storage security? Like clockwork, you can count on a new story appearing every couple of weeks.
In the past month, we've learned of yet another bank sending unencrypted tapes with sensitive data via UPS as well as a health care company using an employee's garage for off-site media storage. In the latter case, the employee's car, which contained backup disks and tapes, was stolen. Interestingly, the tapes actually were encrypted; unfortunately, the disks were not. Too bad the car didn't have LoJack!
Whenever this happens, companies suffer considerable public embarrassment and bear substantial costs in contacting potential victims. While surveys have shown rising interest in data encryption, it still ranks relatively low on IT project lists.
It seems that many companies either remain unaware of the risk (which is hard to believe) or have somehow come to the collective conclusion that the risk and its potential consequences are simply not worth the cost of prevention. Is this true?
While there is no evidence yet that data has been misused, that is little reassurance. What about the cost and effort?
A few years ago, the options for protecting off-site data were costly and few. However, technologies and services now exist that can provide more affordable levels of protection. In-line appliances can encrypt backup data prior to being written to tape with little effect on performance. Several tape drive and library manufacturers have introduced data encryption into their products. Other companies offer remote backup services that store data in an encrypted manner and never require handling of removable media.
To be fair, the maturity of these offerings varies significantly, so one must carefully evaluate and compare the various options. One area requiring particularly scrutiny is encryption key management. For stored data, well-defined key management policies and procedures are critical, and a product that can assist in this complex task is essential.
As more companies adopt encryption policies, the option for others to continue doing nothing becomes less viable. The good news is that this is a problem that has a solution. Now if I could get The Boston Globe to stop recycling reports containing my credit card number to wrap its newspapers?
Jim Damoulakis is chief technology officer of GlassHouse Technologies Inc., a leading provider of independent storage services. He can be reached at jimd@glasshouse.com.
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Speeding business innovation with HP Data Center Transformation solutions
Data center transformation enables your IT organization to focus more on business priorities and innovation by decreasing spending on maintenance and management by...
Four Principles for Reducing Storage TCO
(Source: Hitachi Data Systems) Difficult economic times require new strategies for reducing costs. Where storage technology and economics meet, there are...
HP Data Center Transformation Solutions
CIOs today are challenged to respond to economic and business pressures, to change from being cost centers to becoming strategic business enablers. There...
Boost your CAE productivity, and break-away from the pack
(Source: Sun) Join Clemson University as they present their groundbreaking engineering simulations research at their Computational Center for Mobility Systems. Dr. James Leylek,...
Using Symark PowerBroker to Enrich Your Organization's RBAC Model
The essential notion of Role-Based Access Control (RBAC) for IT security administration is establishing permissions based on the functional roles within the enterprise,...
Deduplication and Other Strategies for Protecting Your Assets with the Veritas NetBackup Platform
(Source: Symantec) Many companies find their backup and storage resources strained by data growth and increased regulatory requirements for data retention. In today's...
Using VMware Site Recovery Manager to Simplify DR
(Source: NetApp) Nothing is scarier than the prospect of having to recover an entire site after a disaster. VMware® Site Recovery Manager (SRM)...
Controlling Email and File Server Growth and Costs with Intelligent Archiving
(Source: Symantec) According to IDC 54% of the storage capacity added by organizations in 2008 will be dedicated to the storage of file-based...
NetApp and VMware Virtual Infrastructure 3 Storage Best Practices
(Source: NetApp) NetApp has been providing advanced storage features to VMware ESX solutions since the product began shipping in 2001. During that time,...
Maximize Storage Assets with Thin Provisioning, Tiered Storage, and Cluster File Systems
(Source: Symantec) Thin Provisioning is an opportunity to immediately optimize your storage systems and make more capacity available to your applications. In order...
Subscribe to Computerworld
