12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 9: Compliance and StorageGLBA and StorageThere is a provision in the GLBA to have “a policy in place to protectthe information from foreseeable threats in security and data integrity”.An integral part of this policy is to encrypt sensitive financialinformation and transactions. There is also a requirement to put inplace the major components of that which is to govern the collection,disclosure, and protection of consumers' nonpublic personalinformation or personally identifiable information.Encryption of data-in-flight, data-at-rest, as well as other SAN andstorage security countermeasures can provide the necessary componentsto protect consumers' nonpublic personal information or PII.Sarbanes-Oxley Act (SOX)The Sarbanes-Oxley Act was enacted on July 30, 2002, as a responseto several corporate and accounting scandals that shook the businessworld at the turn of the century. SOX does not apply to privately-ownedcompanies but to public company boards, management, and publicaccounting firms.Section 404 treats IT controls that specifically address financial risks.Many companies use the COSO (Committee of Sponsoring Organizationsof the Treadway Commission) framework and COBIT (ControlObjectives for Information and Related Technologies) to support SOXsection 404 compliance.SOX and StorageSOX has no direct implications in the storage environment otherthan general system security implications that apply to the storageequipment. In certain cases, there may be some requirements for aminimum retention period for backup data.Export Laws for Cryptographic ProductsUntil recently, cryptographic algorithms and materials were consideredto be munitions, and as such fell under specific export regulations asdictated by each country. Although cryptographic material is no longerconsidered munitions, it is still subject to export regulations in the US.In the US, export of cryptographic material is controlled by the Departmentof Commerce Bureau of Industry and Security (BIS). Somecountries, known as “rogue states”, are strictly forbidden to export162 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!