 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>UK Data Storage Buzz &#187; shared storage</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/storage-buzz-uk/tag/shared-storage/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/storage-buzz-uk</link>
	<description>A SearchStorage.co.UK blog covering the latest data storage news and trends</description>
	<lastBuildDate>Tue, 16 Apr 2013 16:13:21 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Time for a change on internal and external server storage security?</title>
		<link>http://itknowledgeexchange.techtarget.com/storage-buzz-uk/time-for-a-change-on-internal-and-external-server-storage-security/</link>
		<comments>http://itknowledgeexchange.techtarget.com/storage-buzz-uk/time-for-a-change-on-internal-and-external-server-storage-security/#comments</comments>
		<pubDate>Tue, 19 Apr 2011 15:35:17 +0000</pubDate>
		<dc:creator>Ian Lock</dc:creator>
				<category><![CDATA[backup data]]></category>
		<category><![CDATA[dmz]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[ian lock]]></category>
		<category><![CDATA[shared storage]]></category>
		<category><![CDATA[storage security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/storage-buzz-uk/time-for-a-change-on-internal-and-external-server-storage-security/</guid>
		<description><![CDATA[By Ian Lock, GlassHouse Technologies (UK), storage &#38; backup service director Recently I have been asked by several clients about the security of shared storage and backup environments, and in particular whether any element of their storage infrastructure should be shared between internal production and external DMZ servers. The general consensus for many years for [...]]]></description>
				<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0cm 0cm 10pt"><strong><span style="font-size: 10pt;font-family: 'Verdana','sans-serif&amp;quot">By Ian Lock, GlassHouse Technologies (UK), storage &amp; backup service director </span></strong></p>
<div></div>
<p><span style="font-size: 10pt;font-family: 'Verdana','sans-serif&amp;quot"></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt"><span style="font-size: 10pt;font-family: &quot;Verdana&quot;,&quot;sans-serif&amp;quot">Recently I have been asked by several clients about the security of shared storage and backup environments, and in particular whether any element of their storage infrastructure should be shared between internal production and external DMZ servers.<a name="_GoBack"></a></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt"><span style="font-size: 10pt;font-family: &quot;Verdana&quot;,&quot;sans-serif&amp;quot">The general consensus for many years for most of my clients has been a definite ‘no’ to this question; the only link between external and internal networks should be a firewall and nothing else. Such rules are normally written in stone and policed by the security team with draconian penalties for anyone who dares to disobey.</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt"><span style="font-size: 10pt;font-family: &quot;Verdana&quot;,&quot;sans-serif&amp;quot">I have up to now agreed wholehearted with these rules; they’re there for a very good reason, right? They limit the risk of nasty things or people getting to your production data from the outside.</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt"><span style="font-size: 10pt;font-family: &quot;Verdana&quot;,&quot;sans-serif&amp;quot">However, during the course of recent conversations I began to wonder if there wasn’t an argument for some carefully managed sharing of storage resources?</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt"><span style="font-size: 10pt;font-family: &quot;Verdana&quot;,&quot;sans-serif&amp;quot">The question seems to have started to crop up a lot more frequently as storage arrays become more and more ‘unified’ and servers become more and more ‘virtualised’. </span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt"><span style="font-size: 10pt;font-family: &quot;Verdana&quot;,&quot;sans-serif&amp;quot">Companies have realised the benefits of consolidating and virtualising previously separate physical systems to drive down costs, so it goes against the grain to keep discrete storage arrays for production and DMZ. </span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt"><span style="font-size: 10pt;font-family: &quot;Verdana&quot;,&quot;sans-serif&amp;quot">Most centralised backups systems are, after all, allowed to protect servers in the DMZ, as long as the backup data passes through the firewall. And many clients allow virtual machines residing on the same physical hosts to be provisioned for both production and DMZ use. </span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt"><span style="font-size: 10pt;font-family: &quot;Verdana&quot;,&quot;sans-serif&amp;quot">As long as all storage management interfaces and software tools are kept carefully locked down inside a secure internal VLAN, what are the actual risks of presenting a LUN to DMZ and production hosts from the same array?</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt"><span style="font-size: 10pt;font-family: &quot;Verdana&quot;,&quot;sans-serif&amp;quot">Perhaps the answer is to allow sharing of storage resources, but only with better end-to-end security, including tighter intrusion detection systems and maybe encryption of data at rest embedded into storage arrays. That way you get the best of both worlds.</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt"> </p>
<p> </p>
<p></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt"> </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/storage-buzz-uk/time-for-a-change-on-internal-and-external-server-storage-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
