Tech Guide: Storage Security Best Practices
The Storage Networking Industry Association's Storage Security Industry Forum, a trade group devoted to promoting good security techniques, has put together a list of recommended best practices for companies attempting to get a handle on securing networked storage. The association's Web site is at www.snia.org/home .
Its suggestions include:
Identify all interfaces to your storage network.
Create a separate, secure infrastructure for management and control interfaces to the storage network.
Protect data both when it's moving and at rest.
Define storage zones containing the smallest possible number of components.
Use all available local area network security tools such as IPSec and virtual LANs.
Restrict access to infrastructure configuration functions, specifically to all unused ports.
Configure switches so unused ports must be enabled before use.
Install software and firmware only from authorized sources, and don't accept firmware upgrades via the storage-network interfaces.
Always change default passwords before equipment is connected to a production storage network and ensure that strong pass- words are used.
Keep in mind that management ports don't use encryption.
Return to main story, How Secure Is Your SAN?
We welcome your comments on this topic on our social media channels, or
[contact us directly] with questions about the site.
More Insights