Jump to content Worldwide-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
HP.com home
Blogs index  >   Around the Storage Block  

Around the Storage Block

Content starts here
This blog combines the ideas and opinions from many of the data storage experts at HP StorageWorks and provides a platform for sharing information about storage technology, challenges, and of course, opportunities.
» HP Blogging Code of Conduct
Blog categories:  | All

» Unencrypted Tape Creates Security Vulnerabilities

-by Carlos Martinez

One of the top storage security vulnerabilities for enterprises today is unencrypted tape. Most enterprises store tape cartridges off the premises as protection against site disaster. This is a good thing. But the unaccounted for cartridge vulnerability arises during transportation or at a 3rd party storage facility. Considering how much sensitive data can reside on a tape and the volume of cartridges handled, it is only a matter of time before some confidential data has unauthorized exposure. Regulations such as CA SB1386 require public disclosure when unencrypted data is lost or stolen. The majority of the states in the U.S. have similar laws. Even international companies doing business in the U.S. need to heed these laws.

In the 2007 the Ponemon Institute study found that only 11% were encrypting tape and it was single digit prior to that. One can assume that most of this tape encryption was software based. Tape encryption is a much more viable solution today because with embedded native hardware encryption, performance is not compromised and some suppliers including HP include encryption in the drive price. Actually the encryption is the easy part of the equation. What requires serious consideration is the key management system because the volume of the keys will multiple over time and data-at-rest keys can live for many years. Enterprise caliber key management systems addressing tape should integrate with LTO4 and be very automated, secure and redundant. Native tape encryption with solid key management will become standard practice in the enterprise in the not too distant future, and then we’ll see SMBs following right behind. Prevention of a breach is much less costly than addressing it after the fact.

Posted by The Data Storage Experts on Tuesday, March 11, 2008 8:33 AM
PermalinkTrackbacks Comments(0)

Comments for Unencrypted Tape Creates Security Vulnerabilities

No comments posted yet.

Apr May 2008 Jun
SMTWTFS
27282930123
45678910
11121314151617
18192021222324
25262728293031
1234567

XML Feeds
» HP RSS Feeds

Recent blog entries

» Excited about ExDS
» Green Storage #3 – Green Storage and SNIA Unplugged Fest
» Web 2.0 and Cloud Storage
» The Right Write Stuff
» RSA2008 Conference
» Implementing an optimized IT infrastructure takes the right combination of technical building blocks
» Green Storage #2 – Minimizing Environmental Impact
» Thin Provisioning: Why was a Leader a Laggard?
» VDI - a hot technology topic at VMworld Europe
» SRM.... Not your father's Storage Resource Management
» Iomega isn't the only one rejecting EMC's offer
» Unencrypted Tape Creates Security Vulnerabilities
» “Do something with the tapes!” says Joe Tucci
» FCoE…On your mark…get set…Go!
» No, this isn’t your typical Pepsi taste test challenge
» Reflections on this week's EVA 4400 launch
» “Green” Storage – use it to solve real business problems
» Step 1: Admit that IT complexity is making life unmanageable


Printable version
Privacy statement Using this site means you accept its terms