Why Secure Storage Networks?

Storage networks are predominantly used byservice providers for deploying and maintaining the
organisations to centrally manage their data, reducestorage infrastructure. In many cases, the
hardware costs (cost of server hardware, software,management of user permissions on the data is also
installation and maintenance) and downtime (whenoutsourced to the service provider. This adds to the
adding extra storage), effectively manage storagenumber of personnel who could access the
resources, and overcome computing power andorganisations data and the locations where the data
storage scalability issues that the 'independentcan be accessed from (if management is outsourced,
storage for each system' approach is affected with.the storage infrastructure and data could be
These networks are regularly used to store criticalaccessible from all locations where the support staff
information the compromise of which could affectis based).
the organisation's competitive edge, cash-flow,Storage vendors have recently started realising the
profitability, legal and regulatory compliance, andneed for security and are now bundling network
corporate image.storage devices features that help secure the SAN
Storage Area Networks (SANs) and Networkand NAS environments; however, these features are
Attached Storage (NAS) are the two types ofnot configured as factory defaults, and the lack of
storage networks used primarily. The two storagesecure storage configuration policies, standards and
networks differ in various aspects; however, bothguidelines at the organisation/service provider level
these technologies were built with functionality inintroduces considerable weaknesses in the storage
mind and not security, and are riddled withnetwork environment.
vulnerabilities that adversely affect the confidentiality,The security of storage is paramount due to the
availability and integrity of the information storedcriticality of information stored, the abundance of
within these networks. Serious vulnerabilities existsecurity weaknesses in the technology and due to
within these technologies that could allowthe ever growing compliance and regulatory
unauthorised, (and in various cases) unauthenticatedrequirements. The process of securing storage
access to stored information. The support for IPenvironments should start with strict organisational
based connections, iSCSI in SANs, and IP connectionspolicies targeted towards storage networks. Secure
in NAS increase the accessibility but also enlarges theconfiguration standards and guidelines should then be
attack surface.developed and enforced in-line with vendor and
Additionally, organisations often contract third partyindustry best practices.