12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 9: Compliance and StorageFederal Information Security Management Act(FISMA)As the number of security breaches within the US Federal governmentgrew and raised public awareness of protection of information assets,the government was under pressure to implement standards and provideguidelines around IT security. To address these issues, Congressestablished the FISMA Implementation Project in January 2003, to bolstercomputer and network security at specific Federal governmentagencies and affiliated parties by mandating yearly audits.This act was somewhat controversial and some critics felt it hasbecome more an exercise in documentation rather than an improvementin the state of IT security within the Federal government. Theconcern was that government agencies would seek compliance andnot security.FISMA and StorageAlthough there are no specific SAN-related standards or guidelinesin FISMA, it does apply to the information that is stored in a SANenvironment.Chapter SummaryThe storage and SAN component of an IT environment are often subjectto compliance requirements. Compliance guidelines and legislationdescribed in this chapter that apply to the storage and SAN environmentsinclude PCI-DSS, Breach Disclosure Laws, HIPPA, GLBA, FIPS,Common Criteria, and FISMA. Often third parties are required to ensurethe credibility of compliance reports. Cryptographic material, formerlycategorized as munitions, is subject to export regulations in the US.168 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!