Tuesday, March 9, 2010

The Basics of SAN Security

This blog was also published by CIO.com: http://advice.cio.com/solstice_consulting/the_basics_of_san_security

It’s important to protect your organization from malicious threat and from preventing hackers access to sensitive data. You also want to ensure that your organization is compliant with security regulations. When implementing infrastructure projects it’s necessary to ensure that all of the components of the implementation are secure. Storage Area Network or SAN, is one of these components. In laymen’s terms, a SAN is a network that enables storage devices to communicate with other storage devices and computer systems. A SAN uses a high performance network, like fibre channel or Ethernet to communicate, and it typically connects disks and tape drives, RAID subsystems, robotic libraries, and file servers.

As SAN technology becomes more popular, organizations are continuing to evolve their technologies and reap the benefits that SAN has to offer. We all know that computers are attached to some type of storage, but the benefit of a SAN is that it enables Universal Storage Connectivity; the ability to connect many computers to a lot of storage devices allowing computers to negotiate device ownership and share data.

As you integrate SAN into your infrastructure, you also want to make sure that it’s secure. Securing SAN is quickly becoming an important topic, mainly due to the sensitive data that is being transmitted and stored. A method called Zoning is the most common method for managing and securing SAN. It allows you to determine which groups of users can connect with specific storage volumes. It also matches operating systems with their storage. Some of the benefits that Zoning offers include:
• Manageability. Zoning allows you to split SAN up into manageable chunks which makes it easier to keep track of storage and devices
• Security. Zoning allows users to only have access to information they need
• Separation: Zoning allows you to categorize by specific business function or even OS to avoid the possibility of data corruption
• Access: Zoning allows administrators to set up temporary restrictions therefore providing them with greater control

Zoning can be implemented in several different ways and the benefits vary depending on the implementation method. Two common methods of Zoning are “soft” and “hard” zoning. Name server zoning, typically called “soft” zoning, partitions zones based on the World Wide Name (WWN) of devices on the SAN. Port or “hard” zoning allows devices attached to specific ports on a switch to communicate only with devices attached to other ports in the same zone. Name server zoning is the most flexible and easier to set up, where hard zoning is more secure but can create data flow challenges.

When creating SAN architecture for your organization, Zoning is an important aspect to consider when determining security and manageability. Other aspects to consider for a quality SAN implementation include; capacity, availability, performance and scalability. A solid SAN implementation will allow IT organizations to reduce costs and possibly provide new services that were not previously available through legacy storage systems.

0 comments:

Post a Comment