Data center security — what advice would you give?
3330 pts.
0
Q:
Data center security -- what advice would you give?
We've all had our share of "I wish someone would have told me" moments. If you could give advice to someone who is green in data center security, what would be your best piece of advice? What's something you wish someone would have told you early on?
ASKED: Jun 15 2009  7:43 PM GMT
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
0
29855 pts.
0
A:
 RATE THIS ANSWER
0
Click to Vote:
  •   0
  •  0
  • AddThis Social Bookmark Button
Typical Infosec security definition: Confidentiality, Integrity & Availability -

Availabiliity - Power & connectivity.

Be sure that redundant power supplies are actually plugged into separate power sources. Plugging dual power supplies into the same power bus is inviting failure.

Connectivity - don't skimp to begin. Be sure that the users have a good experience from the beginning. Adding capacity can take 30 days or more so a bad end user experience could last for a while if not enough capacity is provisioned up front.

Confidentiality - be sure that who can access the systems is who they say they are and that they are limited in what they can do according to company policy and procedure.

Integrity - backups should be stored separate from the equipment. Don't store the media in the same location as the data. Test the backups regularly to ensure they are doing what you think they are doing.

=============================

Physical access control - Access should be restricted to those who really need to be there, and sign-in procedures should be implemented for visitors. Also, food, drink and smoking must be prohibited inside the data center, and the data center should be monitored by CCTV cameras.
Last Answered: Jun 19 2009  4:31 PM GMT by Carlosdl   29855 pts.
Latest Contributors: Mrdenny   46810 pts., Labnuke99   26290 pts.
0
0
Discuss This Answer:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _



_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _

JennyMack   3330 pts.  |   Jun 15 2009  9:00PM GMT

Thanks Labnuke, that was a great answer!

 

JennyMack   3330 pts.  |   Jun 15 2009  9:12PM GMT

Mrdenny, I saw that you changed Labnuke’s answer from testing backups “occasionally” to “regularly” — a valid point. What kind of schedule would you advise?

 

KevinBeaver   7610 pts.  |   Sep 30 2009  5:06PM GMT

I’d add including data centers in your risk assessments. They’re often overlooked while, at the same time, are often creating many risks to the business.

 

mrdenny   46810 pts.  |   Oct 5 2009  6:01PM GMT

Backup tests should be done at least monthly, and preferably be automated so that they aren’t skipped when people are out on vacation, etc.

 
0