12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 4: Security Basics for Storage ProfessionalsInformation Disposal and SanitizationEventually, all storage media will end its useful life and will need to bedisposed. A storage media may end its life prematurely when a diskdrive or tape cartridge is defective. Typically, a storage vendor willreplace a defective disk drive with a new one then refurbish and recyclethe old one. In most cases, the defective disk drive is sent to atesting facility, where it is run through diagnostic tests and, in manycases, refurbished and sent back to the field. A proper refurbishingprocess should also wipe out pre-existing data according to a specifiedmethod, which may vary between vendors. Vendors generally takegreat measures to ensure that no customer data remains on refurbisheddisks, but there have been reported cases of customersreceiving new drives that contained live data from a previouscustomer.There is also the technology refresh issue. Once an organizationchooses to refresh their storage arrays with newer models, or with a differentvendor's products, older arrays are often swapped out as part ofa deal. As with failed disk drives, all disks should be properly sanitized,but sometimes old units are put on the second-hand market withoutprior data sanitization. With numerous reported cases of storage mediaon the second-hand market containing live data, data disposal andsanitization has gained public attention from the media, risk managementteams in the corporate world, and government organizationsalike.Data SanitizationData disposal and sanitization deals with maintaining confidentiality ofinformation. Evidently, not all stored data needs to be destroyed orsanitized, and the degree to which it needs to be sanitized depends onthe sensitivity and importance of the data as well as the risk of exposureto the company if the data were stolen. Certain industriesregulate how certain types of data should be sanitized, while otherindustries are governed by legislation specifying what and how datashould be destroyed.The first step in developing a data destruction and sanitization strategyis to classify the data to identify which types of data require specialsanitization and/or destruction requirements. Once the data has beenidentified, the level of sanitization to be performed should then bedetermined.68 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!