12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Who Needs to Know About SAN and Storage Security?Chief Executive Officer (CEO). The company CEO obviously has a highlevelconcern for SAN and storage security, but her focus is in two specificareas: the potential liability resulting from security breaches andnon-compliance with industry and government regulations. For someexecutives, liability may in fact equate to jail time.Chief Information Officer (CIO). The CIO is usually responsible for theIT department, which owns network, SAN, storage, and other technologies.Protecting these assets and minimizing risk and liability due to asecurity breach is paramount in this role. This role may extend beyondthe technology and, in some cases, may include the actual informationthat is stored, processed, and managed.Chief Financial Officer (CFO). The CFO is typically concerned from acompliance and regulatory perspective. The auditing department oftenfalls under the CFO, making sure that appropriate controls are in placeto guide the construction of policies and enforce them.Chief Compliance Officer (CCO). The CCO’s role is to ensure that thecompany is complying with local, state, federal, and industry regulations.He reviews the various regulations and creates the necessaryprograms to comply with these regulations. He often works in collaborationwith the audit team to ensure that all regulations are beingfollowed. The CCO frequently reports to the CFO.Chief Security Officer (CSO)/Chief Information Security Officer(CISO). The CSO, or the CISO, is directly responsible for the protectionof the IT assets and sometimes this extends to protecting all companyassets including facilities and personnel. The SAN is of particular concernto the CSO/CISO since the data residing on it is one of thecompany’s most valuable assets.IT Security Director/Manager. The IT security director or manager’sprimary concern is with the IT assets, applications, and personnel thatshe is responsible for. Her concern with the SAN and storage environmentis more detailed and she is responsible for implementing manyof the controls and policies established by the C-level executives.Security Professional. The security professional can be responsiblefor creating security policies, implementing security measures, managingthe security aspects of the IT environment, monitoring the state ofsecurity of the IT environment, and responding to security incidents.He should have a direct involvement in the SAN and storage securityjust as he would with the corporate LAN and server environment. QuiteSecuring Fibre Channel Fabrics 7

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!