Logo Rob Buckley – Freelance Journalist and Editor

Information protection

Information protection

Ensuring the integrity of information is a primary goal of both security and storage, a fact that puts the sectors on a converging course.

Page 1 | Page 2 | Page 3 | All 3 Pages

The other main problem the SAN has introduced is making storage a shared resource. Yet, without a unified security framework, potentially dozens of different hosts, each with their own security policies, users and passwords, could be accessing the shared storage and granting access to data that other hosts would not.

For all these reasons, various organisations (and now storage vendors) have begun to look at encrypting data when it is at rest, whether that is on disk or tape.

“I’ve often asked why more organisations don’t use encryption,” says storage practice manager Darren Thorne of consultancy Logicalis. “It seems so obvious. No one seems to know why it hasn’t been considered more seriously in the commercial space before now. The NHS is very aware of the sensitivity of its data. Central government and the MoD already regularly encrypt data.”

Specialist vendors in this area, such as Decru and NeoScale, have been carving niches for themselves with hardware appliances that encrypt and decrypt data to and from disk and tape at “wire speed” – that is, without introducing the latency and speed constraints that have traditionally accompanied encryption.

“The perimeter is porous now,” argues Joanna Shields, VP EMEA at Decru. “Large businesses need to collaborate with their suppliers, their consultants, contractors and business partners. If you want to do that, putting up a firewall just isn’t going to do the job since you need to give these people access to your information.”

The appliances sit between the storage system and the servers so that the data is encrypted as it is generated and stored. When host users try to access it, provided they have the appropriate permissions, the data will be decrypted transparently.

Since the data is encrypted it is possible to pass the storage unit or indeed the data to third-parties without concern that it will be misappropriated, something that companies that outsource their data storage are starting to appreciate, Shields says.

By encrypting data, says Shields, an organisation is able to separate two job functions that are normally combined: the ability to manage data and the ability to read data. Once data is encrypted, any appropriate systems administrator can handle it, without there being concerns of whether he or she should be allowed to have access to it.

Encryption is also being posited as a necessary response to certain laws and compliancy regulations. Bob Zimmerman, an analyst with Forrester Research, points out that Californian law requires any company whose IT systems are known to have been compromised to inform everyone whose personal data has potentially been exposed unless the data fields were encrypted.

Product releases
Decru is not the only company that has woken up to encryption. IBM has added encryption facilities to its DS6000 product and EMC plans to build encryption and data compression into its Centera system – it already secures information using computer-generated software key codes.

Page 1 | Page 2 | Page 3 | All 3 Pages

Interested in commissioning a similar article? Please contact me to discuss details. Alternatively, return to the main gallery or search for another article: