<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/online/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Around the Storage Block Blog : security</title><link>http://www.communities.hp.com/online/blogs/datastorage/archive/tags/security/default.aspx</link><description>Tags: security</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>NPI Day Part 2</title><link>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/11/17/npi-day-part-2.aspx</link><pubDate>Mon, 17 Nov 2008 23:00:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:86654</guid><dc:creator>CalvinZ</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/datastorage/rsscomments.aspx?PostID=86654</wfw:commentRss><comments>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/11/17/npi-day-part-2.aspx#comments</comments><description>&lt;p&gt;By Calvin Zito&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In &lt;a href="http://www.communities.hp.com/online/blogs/datastorage/archive/2008/11/17/npi-day.aspx" target="_blank"&gt;&lt;strong&gt;my previous post&lt;/strong&gt;&lt;/a&gt;, I talked a little bit about our New Product Introduction (NPI) process and gave some pointers to a number of things that came from the latest NPI.&amp;nbsp; Here are a few more things to highlight:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;We announced the HP StorageWorks SAN Virtualization Platform a couple of weeks ago - you can see the product page at &lt;a href="http://www.hp.com/go/SVSP" target="_blank"&gt;&lt;strong&gt;www.hp.com/go/SVSP&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp; &amp;nbsp;&lt;/li&gt;
&lt;li&gt;We also had publicly announced updates to the StorageWorks Secure Key Manager at SNW Dallas back in mid-October.&amp;nbsp; You can learn more about the enhancements at &lt;a href="http://www.hp.com/go/storagesecurity"&gt;&lt;strong&gt;www.hp.com/go/storagesecurity&lt;/strong&gt;&lt;/a&gt; or on the &lt;u&gt;&lt;strong&gt;&lt;a href="http://h18006.www1.hp.com/products/storageworks/secure_key/index.html" target="_blank"&gt;product page&lt;/a&gt;&lt;/strong&gt;&lt;/u&gt;.&amp;nbsp; &lt;/li&gt;
&lt;li&gt;We also announced new functionality on our XP24000 and XP20000 Disk Array family.&amp;nbsp; You can learn about the XP enhancements on the &lt;strong&gt;&lt;u&gt;&lt;a href="http://h18006.www1.hp.com/products/storageworks/xp24000/index.html" target="_blank"&gt;XP Disk Array product page&lt;/a&gt;&lt;/u&gt;&lt;/strong&gt;.&amp;nbsp; Jim Hankins is writing a blog about External Storage Disaster Recovery with details so I won&amp;#39;t spoil his fun.&amp;nbsp; Also new with the XP is support for Solid State Storage Technology.&amp;nbsp; One of our competitors predicted that we wouldn&amp;#39;t have solid state storage technology until 2009.&amp;nbsp; I think we beat that by a bit.&amp;nbsp; Now we have solid state for both our BladeSystem and XP disk array with more to come.&amp;nbsp; No hype, just keeping it real!&lt;/li&gt;
&lt;li&gt;Utility Ready Storage is an interesting solution that we&amp;#39;ve offered for a while and I&amp;#39;m guessing will get more interesting for customers with the looming economic situation.&amp;nbsp; There are some new services with Utility Ready Storage and a very good feature article describing it.&amp;nbsp; Here&amp;#39;s a link to the article: &lt;a href="http://h71028.www7.hp.com/services/library/GetPage.aspx?pageid=618132&amp;amp;statusid=0&amp;amp;audienceid=0&amp;amp;ccid=0&amp;amp;langid=121" target="_blank"&gt;&lt;strong&gt;Aligning storage costs and usage with Utility Ready Storage&lt;/strong&gt;&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;I&amp;#39;ve only touched on some of the NPI enhancements today but hopefully I&amp;#39;ve given you a small glimpse into what is going on.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;Calvin Zito&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=86654" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/security/default.aspx">security</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/virtualization/default.aspx">virtualization</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/solid+state+storage+technology/default.aspx">solid state storage technology</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/Utility+Ready+Storage/default.aspx">Utility Ready Storage</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/storage/default.aspx">storage</category></item><item><title>Storage Security at SNW</title><link>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/10/13/storage-security-at-snw.aspx</link><pubDate>Mon, 13 Oct 2008 16:36:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:86115</guid><dc:creator>CalvinZ</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/datastorage/rsscomments.aspx?PostID=86115</wfw:commentRss><comments>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/10/13/storage-security-at-snw.aspx#comments</comments><description>&lt;p&gt;This week is the fall &lt;a class="" href="http://www.snwusa.com/" target="_blank"&gt;&lt;strong&gt;Storage Networking World&lt;/strong&gt;&lt;/a&gt; in Dallas.&amp;nbsp; At the show, we made &lt;a class="" href="http://www.hp.com/hpinfo/newsroom/press/2008/081013b.html" target="_blank"&gt;&lt;strong&gt;an announcement today&lt;/strong&gt;&lt;/a&gt; focused on storage security - a topic growing in importance.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;Threats to storage security are real and can be a significant liability.&amp;nbsp; Seems as though not a week goes by in the press without another story of some data being lost, stolen or hacked. And there is a cost associated with these type of breaches.&amp;nbsp; Here&amp;#39;s an interesting &lt;a class="" href="http://www.tech-404.com/calculator.html" target="_blank"&gt;&lt;strong&gt;web-based tool from Tech//404&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;that calculates the cost of data loss from security breaches and identity theft.&amp;nbsp; The site also talks about a number of class action suits with class sizes ranging from a quarter of a million people to two million seeking damages in the range of $1,000 to $21,000 per person in the class.&amp;nbsp; There could be some mind-boggling settlements.&lt;/p&gt;
&lt;p&gt;Encryption is relatively easy - managing keys is the challenge.&amp;nbsp; Multiple key management systems increases complexity and lowers the success of recovery.&amp;nbsp; We believe&amp;nbsp;that centralized key management trumps a disparate systems approach because it&amp;#39;s more efficient and offers better data availability.&amp;nbsp; Today&amp;#39;s announcement has two components:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div&gt;Enhancements to our &lt;a class="" href="http://h18006.www1.hp.com/products/storageworks/secure_key/index.html" target="_blank"&gt;&lt;strong&gt;HP StorageWorks Secure Key Manager&lt;/strong&gt;&lt;/a&gt; - increasing the capacity to 2 million encryption keys per cluster and lowered entry price with a single client/node configuration.&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Disk encryption for the XP24000 and XP20000 -&amp;nbsp;&amp;nbsp; encrypts data on disk drives so that data can not be read off a disk drive that is removed without having the key.&amp;nbsp; Here&amp;#39;s a &lt;a class="" href="http://h71028.www7.hp.com/ERC/downloads/4AA2-2629ENW.pdf" target="_blank"&gt;&lt;strong&gt;short white paper&lt;/strong&gt;&lt;/a&gt; that talks about the XP disk encryption.&amp;nbsp; &lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;We have &lt;a class="" href="http://h71028.www7.hp.com/enterprise/cache/554039-0-0-0-121.html" target="_blank"&gt;&lt;strong&gt;a web page&lt;/strong&gt;&lt;/a&gt; that has a number of white papers, including from a leading analyst firm Enterprise Strategy Group, and other information on today&amp;#39;s announcement.&amp;nbsp; While the announcement today focuses on storage, we have a broader security initiative called &lt;a class="" href="http://h71028.www7.hp.com/enterprise/cache/512540-0-0-0-121.html" target="_blank"&gt;&lt;strong&gt;HP Secure Advantage Solutions&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp; We&amp;#39;re driving solutions that protect data, protect resources, and provide validation.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;Here&amp;#39;s hoping your data is secure and that we have a more secure week in the financial markets.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=86115" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/security/default.aspx">security</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/storage/default.aspx">storage</category></item><item><title>I've been personally impacted by lost tapes</title><link>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/09/17/i-ve-been-personally-impacted-by-lost-tapes.aspx</link><pubDate>Wed, 17 Sep 2008 17:55:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84785</guid><dc:creator>jim hankins</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/datastorage/rsscomments.aspx?PostID=84785</wfw:commentRss><comments>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/09/17/i-ve-been-personally-impacted-by-lost-tapes.aspx#comments</comments><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Hi Folks,&lt;/p&gt;
&lt;p&gt;Yesterday I received a letter in the mail at home that&amp;nbsp;started off:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;font color="#0000ff"&gt;Dear Sir or Madam,&lt;/font&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;font color="#0000ff"&gt;We are writing to let you know that computer tapes containing some of your personal information were lost while being transported to an off-site storage facility by our archive services vendor. While we have no reason to believe that this information has been accessed or used inappropriately, we deeply regret that this incident occurred....&lt;/font&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;So the first question I have is how does an archive vendor lose tapes? How hard can it be to take the tapes from your customer put them in a secure truck and drive them to the storage facility? Isn&amp;#39;t that your whole business model -&amp;nbsp;you will pick up, transport and store these tapes safely and securely&amp;nbsp;100% of the time? &lt;/p&gt;
&lt;p&gt;Now I understand that any activity with humans involved cannot be guaranteed to work 100% of the time. So what really happened? A bit more of an explanation would have been helpful, such as the truck was in an inadvertent accident and the contents of the truck were spilled into a river or all over the highway and could not all be recovered. Without more details&amp;nbsp;I&amp;#39;m left wondering did someone make off with the tapes by accident or on purpose? Or was this just sloppy work by the company?&lt;/p&gt;
&lt;p&gt;Anyway, I hope this is a call to action for this company to do at least two things to prevent such an incident in the future.&lt;/p&gt;
&lt;p&gt;1. Look into tape encryption such as the LTO-4 offers. I would have been more much pleased if that second sentence read &amp;quot;While the tapes were physically lost, the data they contained&amp;nbsp;cannot be accessed or read by anyone because the data on the tapes&amp;nbsp;is securely encrypted&amp;nbsp;with sophisticated technology requiring encryption keys to make the&amp;nbsp;data readable.&amp;nbsp;Our security policy ensures that these keys are always stored in or transported&amp;nbsp;to physically separate locations from the computer tapes.&amp;quot;&lt;/p&gt;
&lt;p&gt;2. Consider the use of replication and electronic vaulting for moving data off-site for archiving. With new technologies such as deduplication and low-bandwidth replication, this company would&amp;nbsp;perhaps be able to&amp;nbsp;reduce the amount of data that is stored on tapes and physically transported to archive storage. Again, I don&amp;#39;t know the specifics here, but as an example let&amp;#39;s say this company had four sites that they were backing up to data to tape and transporting those tapes to off-site archives. With replication and electronic vaulting, they could&amp;nbsp;replicate data from three of their sites to just one site&amp;nbsp;for backup to tapes and then only have to move tapes from the one site to archive storage&amp;nbsp;thereby reducing their risk exposure by 75%.&lt;/p&gt;
&lt;p&gt;If you&amp;#39;re worried about how a similar incident could impact your company and what risks are involved HP&amp;nbsp;is here to&amp;nbsp;help. We can work with you to significantly reduce your data security exposure from the desktop to your data center.&amp;nbsp;On the storage side, we offer a FREE &lt;a href="https://h30328.www3.hp.com/BCAQSS/ui/forms/questionnaire/Default.aspx?lc=en&amp;amp;cc=us&amp;amp;cid=1" target="_blank"&gt;storage security risk assessment&lt;/a&gt;. For more details on HP&amp;#39;s other data security options beyond storage please check &lt;a href="http://h71028.www7.hp.com/enterprise/cache/512540-0-0-0-121.html"&gt;HP&amp;#39;s Security web page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;font color="#0000ff"&gt;&lt;/font&gt;&lt;/em&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84785" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/tape/default.aspx">tape</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/LTO+Ultrium/default.aspx">LTO Ultrium</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/deduplication/default.aspx">deduplication</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/backup/default.aspx">backup</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/Virtual+Library+System/default.aspx">Virtual Library System</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/virtual+tape/default.aspx">virtual tape</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/disk-based+backup/default.aspx">disk-based backup</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/security/default.aspx">security</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/D2D+Backup+Systems/default.aspx">D2D Backup Systems</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/storage/default.aspx">storage</category></item><item><title>How are you securing your unstructured data?</title><link>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/07/03/how-are-you-securing-your-unstructured-data.aspx</link><pubDate>Thu, 03 Jul 2008 17:04:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83588</guid><dc:creator>jim hankins</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/datastorage/rsscomments.aspx?PostID=83588</wfw:commentRss><comments>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/07/03/how-are-you-securing-your-unstructured-data.aspx#comments</comments><description>&lt;p&gt;&lt;font size="2"&gt;-by Jim Hankins&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font size="2"&gt;We&amp;#39;ve all being hearing about&amp;nbsp;the difficulties of&amp;nbsp;deploying enough storage to keep up&amp;nbsp;with the growth of unstructured data (email, Microsoft Word, PowerPoint, audio, video, etc.). &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font size="2"&gt;I just saw&amp;nbsp;this article over at Computerworld, &lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoPlainText" style="MARGIN:0in 0in 0pt;"&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9105818"&gt;&lt;font face="Consolas" size="2"&gt;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9105818&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;font size="2"&gt;that says not only is storage growth a problem, but only 23% of IT professionals believe that unstructured data is&amp;nbsp;being adequately secured in their companies. Have you been thinking about this issue at your company? Could you be putting your company at risk or perhaps even your job if one of these pieces of unstructured data gets into the wrong hands?&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;We have a&amp;nbsp;FREE tool that allows you to assess the security of your storage and backup environment. Give it a try at: &lt;a href="http://www.hp.com/storage/securityassessment"&gt;www.hp.com/storage/securityassessment&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Also, if you have a few minutes take a look at our Storage Security solutions at: &lt;a href="http://www.hp.com/go/storagesecurity"&gt;www.hp.com/go/storagesecurity&lt;/a&gt; or if you are&amp;nbsp;looking for security solutions across other areas of your IT infrastructure please take a look at our Secure Advantage portfolio &lt;a href="http://www.hp.com/go/security"&gt;www.hp.com/go/security&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;And have a safe, &lt;em&gt;&lt;u&gt;secure&lt;/u&gt;&lt;/em&gt; and happy 4th of July!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9105818"&gt;&lt;font face="Consolas" size="3"&gt;&lt;/font&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83588" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/security/default.aspx">security</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/storage/default.aspx">storage</category></item><item><title>RSA2008 Conference</title><link>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/04/08/HPPost6136.aspx</link><pubDate>Tue, 08 Apr 2008 12:13:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:78513</guid><dc:creator>BlogArchive</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/datastorage/rsscomments.aspx?PostID=78513</wfw:commentRss><comments>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/04/08/HPPost6136.aspx#comments</comments><description>&lt;p&gt;- by Carlos Martinez&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;With 17,000 attendees and over 350 exhibitors the RSA2008 Conference can be an intimidating experience for IT storage professionals who are investigating privacy solutions for data-at-rest. HP is a comforting and familiar face for these storage professionals because they know HP is committed to both storage and security with the power of our Secure Advantage portfolio. HP addresses security holistically from the desktop to the data center to protect resources, data and provide validation for audits.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;HP StorageWorks has several new Secure Advantage proof points to display at the RSA show including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A fabric switch designed to offer privacy for legacy tape data. &lt;/li&gt;
&lt;li&gt;A simple encryption kit single tape autoloaders and small libraries. &lt;/li&gt;
&lt;li&gt;Integration of the Secure Key Manager with the HP Compliance Log Warehouse to extend our value for compliance. &lt;/li&gt;
&lt;li&gt;The new HP Storage Security Assessment tool enables customers to gauge their data protection privacy vulnerabilities online and free of charge. &lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Data-at-rest is a huge privacy risk but HP is definitely there to help with solutions, tools and services which you can see demonstrated here at the RSA Conference.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=78513" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/security/default.aspx">security</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/storage/default.aspx">storage</category></item><item><title>Unencrypted Tape Creates Security Vulnerabilities </title><link>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/03/11/HPPost5907.aspx</link><pubDate>Tue, 11 Mar 2008 12:33:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:78504</guid><dc:creator>BlogArchive</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/datastorage/rsscomments.aspx?PostID=78504</wfw:commentRss><comments>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/03/11/HPPost5907.aspx#comments</comments><description>&lt;p&gt;-by Carlos Martinez&lt;br /&gt;&lt;br /&gt;One of the top storage security vulnerabilities for enterprises today is unencrypted tape. Most enterprises store tape cartridges off the premises as protection against site disaster. This is a good thing. But the unaccounted for cartridge vulnerability arises during transportation or at a 3rd party storage facility. Considering how much sensitive data can reside on a tape and the volume of cartridges handled, it is only a matter of time before some confidential data has unauthorized exposure. Regulations such as CA SB1386 require public disclosure when unencrypted data is lost or stolen. The majority of the states in the U.S. have similar laws. Even international companies doing business in the U.S. need to heed these laws.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In the 2007 the Ponemon Institute study found that only 11% were encrypting tape and it was single digit prior to that. One can assume that most of this tape encryption was software based. Tape encryption is a much more viable solution today because with embedded native hardware encryption, performance is not compromised and some suppliers including HP include encryption in the drive price. Actually the encryption is the easy part of the equation. What requires serious consideration is the key management system because the volume of the keys will multiple over time and data-at-rest keys can live for many years. Enterprise caliber key management systems addressing tape should integrate with LTO4 and be very automated, secure and redundant. Native tape encryption with solid key management will become standard practice in the enterprise in the not too distant future, and then we’ll see SMBs following right behind. Prevention of a breach is much less costly than addressing it after the fact.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=78504" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/security/default.aspx">security</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/storage/default.aspx">storage</category></item><item><title>EMC/RSA: Key Management? Nice try... (Part 2)</title><link>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/02/05/HPPost5679.aspx</link><pubDate>Tue, 05 Feb 2008 19:07:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:78484</guid><dc:creator>BlogArchive</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/datastorage/rsscomments.aspx?PostID=78484</wfw:commentRss><comments>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/02/05/HPPost5679.aspx#comments</comments><description>&lt;p&gt;Last time, I talked about how EMC’s key management product didn’t quite live up to ours hardened appliance. Here, I’ll go into the nitty-gritty details of why this is true. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The SKM is a preconfigured server and key management application with no other software loadable by the user or an attacker. Furthermore, unnecessary ports and services are disabled; it features built-in strong user authentication and is physically hardened. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;No doubt, enterprises that are serious about privacy would consider the many practical security advantages of a hardened appliance. The SKM fits the bill in this regard because it’s complete and already locked down “out-of-the-box,” whereas the user would have to procure the HW and OS, and do all the installing and configuring with a software key management product and hope they didn&amp;#39;t miss anything. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Their additional challenge would be to keep tight control over root access forever. HP is so adamant about striving for excellence in user confidence in the SKM that we’re undergoing the very rigorous FIPS 140-2 cryptographic validation process and subjecting it to review by an accredited independent laboratory (Check out the NIST &lt;a href="http://www.nist.gov/"&gt;&lt;u&gt;website&lt;/u&gt;&lt;/a&gt;). &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;EMC/RSA does not have a key management product undergoing this process, though they do have limited toolkit and discrete components that have been validated.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Additional areas the SKM shines over EMC/RSA key management solutions are high availability, clustering and failover. The SKM boasts multiple layers of redundancy and DR: dual AC power, dual power supplies, dual network paths and mirrored disk – all in the appliance itself. The minimum 2-node SKM cluster automatically and transparently replicates keys and policy configuration across all cluster members. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Key management clients rotate across all available SKMs automatically by tier for geographic failover. The SKM features internal and external backup and provides the ability to recover a node or cluster from a backup and bare metal if needed.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Unencrypted tape is a privacy vulnerability enterprises are grappling with today. EMC/RSA needs to partner with 3&lt;sup&gt;rd&lt;/sup&gt; party vendors that must inject costly encryption appliances; conversely the SKM integrates seamlessly with the embedded hardware encryption capability on HP LTO-4 enterprise libraries. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;HP allows flexibility in security policies such as a key/cartridge or a key/library partition. And practically, this allows incorporation of encryption at the customer’s pace as opposed to a forklift upgrade or being relegated to legacy tape solutions.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Carlos Martinez&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=78484" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/security/default.aspx">security</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/storage/default.aspx">storage</category></item><item><title>EMC/RSA: Key Management? Nice try... (Part 1)</title><link>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/02/05/HPPost5674.aspx</link><pubDate>Tue, 05 Feb 2008 02:27:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:78483</guid><dc:creator>BlogArchive</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/datastorage/rsscomments.aspx?PostID=78483</wfw:commentRss><comments>http://www.communities.hp.com/online/blogs/datastorage/archive/2008/02/05/HPPost5674.aspx#comments</comments><description>&lt;p&gt;&lt;strong&gt;Posted by Carlos Martinez&lt;/strong&gt; &lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Storage security: Yet another area where EMC is playing catch up to HP StorageWorks. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;EMC spent over $2 billion on the RSA acquisition in 2006 and still does not have an enterprise-caliber encryption key management solution. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;We, on the other hand, quietly leveraged the HP Secure Advantage experts to develop the &lt;a href="http://www.hp.com/go/encryption"&gt;&lt;u&gt;Secure Key Manager (SKM)&lt;/u&gt;&lt;/a&gt;, which was announced last October.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;HP Secure Advantage key management architecture is designed to accommodate future encrypting clients of various types and technologies across the infrastructure. HP is aggressively advocating key management standards that will maximize cross-portfolio and cross-vendor interoperability in the long run. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;With HP’s breadth of storage, servers, applications, printing and mobile devices we have a vested interest in pursuing centralized key management. Storage pure-plays like EMC will be challenged to make this happen infrastructure wide.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;To be honest, no one has “arrived” yet when it comes to “THE” secure key management solution, but HP is certainly leading EMC/RSA and others in proving the enterprise-caliber solution the industry is asking for. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=78483" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/security/default.aspx">security</category><category domain="http://www.communities.hp.com/online/blogs/datastorage/archive/tags/storage/default.aspx">storage</category></item></channel></rss>