Storage Tip: Access storage arrays remotely, securely

By David Hill, Mesabi Group |  Storage Add a new comment

What seems to be the problem? Storage arrays have long had the capability to
communicate information of the array from the physical site where the arrays
are located to a remote location. The first instantiation of this was the "call
home" capability where an array could be accessed over a telephone line
by a third party -- typically an employee of the storage vendor that provided
the array. Now, of course, messages can be sent over the Internet or through
wireless capabilities, such as to a cell phone or a Blackberry. Is it safe to
do?

What you need to know: The ability of a storage array to communicate remotely
has evolved over the years. The first reason was to monitor the health of the
array. If a disk failed, a storage vendor would know it immediately and could
dispatch a repair person to replace the failed disk. This reduced the time of
exposure to a possible second disk failure before a single parity RAID group
could be rebuilt. The ability to communicate health information evolved into
the ability to send information over an Ethernet connection, such as an e-mail
message.

While the ability to use different communication channels has evolved, so has
the ability to gather different types of information. Configuration information
is one type, but so is capacity utilization information as well as information
on the behavior of applications, such as a backup application.

This information is not only for monitoring purposes (i.e. read-only information),
but also control-oriented purposes (i.e. write actions to change things). So,
if an unauthorized user can read information, it is a breach of confidentiality,
but if an unauthorized person can make unauthorized changes, it could create
serious problems.

Therefore, while having the ability to act remotely may be highly desirable,
it must be done safely.

What you can do about it: There are a number of choices that will enable you
to have remote management capabilities, and make sure that you have the necessary
security. Among the options that you can consider include:

* If possible, don't provide always on service (24x7) if the service can
be restricted to certain times, on a scheduled basis, or an on request basis.
(That may not be possible for read-only monitoring, but may be possible in some
cases where write actions need to be performed.)


* Encrypt in transit communications to prevent interception of confidential
information by an unauthorized third party.


* Make sure that information is available only to those on a need-to-know
basis so that only people who really must be authorized are authorized.


* Make sure that the proper access controls are in place so that only authorized
users can access the information.


* Make sure that all write actions are logged in an auditable fashion.

Your business can benefit from remote management, but take the necessary actions,
such as those above, to ensure security.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    StorageWhite Papers & Webcasts

    White Paper

    AppAssure vs Acronis

    In this study of data protection for environments with virtual and physical servers running Windows, openBench Labs tested AppAssure Backup and Replication software v 4.7 and Acronis Backup & Recovery 11. Both solutions utilize block-based technology to unify data protection operations.

    White Paper

    Guaranteeing 100% Backup Recovery

    The single biggest challenge for IT personnel involved in the data protection process is making sure that their backups are recoverable every time. Management and users won't remember the ninety-nine successful recoveries but they will always remember the one failure.

    White Paper

    ESG Analyst White Paper - VMware's vSphere Storage Appliance: High Availability for Small IT Operations

    Learn how small and midsized businesses are increasingly adopting virtualisation to deliver consolidation, improve data back up and disaster recovery and increase security with an in-depth new paper from the Enterprise Strategy Group (ESG). Learn directly from your peer's experiences and see why VMware's solutions are perfect for the growing and ambitious business.

    Webcast On Demand

    Understand Your Data: The Future of Backup and Archiving

    Archiving and Backup are the foundation of the next generation of information governance. However, commodity data protection tools and basic archives are only good for storing data. In the changing IT landscape, understanding what you are keeping, when to delete, and delivering insight to the business from your data is the future of these systems. Join us to hear the impact of private and public cloud solutions, "big data" and your choices while market evolves.

    Sponsor: Autonomy

    White Paper

    NetVault: #1 in the 2011 Oracle Backup Solutions Buyer's Guide

    Want to know how NetVault Backup compared against other Oracle backup software solutions - and why it's DCIG's #1 choice? In this 37-page report you'll get unbiased, third-party evaluations of Oracle backup software - and why NetVault Backup sits on the top of the list. Download your copy today.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question