12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 9: Compliance and StoragePCI-DSS and StorageSeveral requirements defined in the PCI-DSS affect the SAN andstorage environments, specifically:• Requirement 3.4.1 refers to the possible use of disk encryptionto protect cardholder data.• Requirement 3.5 and 3.6 refer to protecting the keys used toencrypt cardholder data.• Requirement 4.1 addresses encryption of data-in-flight whentransmitting sensitive information over open, public networks.Protocols such as SSL/TLS and IPSec are recommended.• Several other requirements mandate the use of secure managementinterfaces, such as SSH and SSL.• Other requirements define system security parameters, suchas synchronizing system clocks (10.4).Breach Disclosure LawsThe recent increase in news articles and public display of securitybreaches in the US and worldwide is largely attributable to recent lawsforcing organizations to disclose security breaches or risk penalties.Several websites are dedicated to publishing these security breaches:• Privacy Rights Clearinghouse:http://www.privacyrights.org/• Open Security Foundation Data Loss DB:http://datalossdb.org/• Office of Inadequate Security:http://www.databreaches.net/Breach disclosure laws require organizations to disclose specific typesof security breaches, particularly those involving personally identifiableinformation (PII) of individuals of a given state. There is no currentfederal legislation to address breach disclosure.158 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!