Storage - Baseline
Home arrow Storage arrow Page 3 - Is Stored Data Safe Data?













Renew Your Subscription

Storage



Is Stored Data Safe Data?



By Doug Bartholomew

  Table of Contents:
  1. Is Stored Data Safe Data?
  2. Data Behind the Firewall
  3. Is Encryption Overkill?

What measures can organizations take to improve the security of at-rest customer, product and employee data? Experts weigh in.

Rate This Article:
Add This Article To:

Is Stored Data Safe Data? - Is Encryption Overkill?


( Page 3 of 3 )




Baseline:  Is encryption the best way to secure stored data, or is it overkill? What alternatives are available?

Proctor:  Encryption is a good way to secure stored data. But it comes at a great cost in many environments, at the expense of database/application performance, key management costs, and application development costs.

Encryption is not a panacea. In many cases enterprise-wide encryption is expensive overkill. Some alternatives would include classifying data and selectively encrypting high-value data, obscuring data in sensitive fields, managing access control, and monitoring administrative access.

There are dozens of possible controls. One of the more popular today is data loss prevention technology that can detect sensitive data-on-the-fly and encrypt it, or delete it as necessary.    

Woo:  Encryption can occur on many levels. In my non-network, non-security-oriented brain, object/file encryption is the best. However, it does come with severe costs: namely, that of key management. Alternatives such as full-disk encryption provide adequate protection, and at least in many of the implementations I’ve seen, require only minimal key management. The economic factor is not the cost of encryption, but rather the cost of not encrypting. If a file is encrypted, then by definition, it is inaccessible without the appropriate key(s). This approach is actually quite simple, but complex to implement. 

The most critical thing for our industry is that storage, network, and security functions are converging, and we must adapt to this convergence. The current virtualization trend only adds additional layers of sophistication and complexity.

There is no silver bullet in addressing this issue of data security. Each organization needs to do a loss analysis in order to properly ascertain the degree to which their data needs to be secured.  
 



 
 
>>> More Storage Articles          >>> More By Doug Bartholomew
 


Sponsored Links
  • Get up and running in as quickly as 30 days with BI. Learn how today.

  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • Build an IT Infrastructure That Delivers the Future
     
  •  
    FEATURED SPONSORED ARTICLES

    FEATURED SPONSORED VIDEOS

     



    LATEST STORIES


     

     


    Advertisement
    rss graphic
           Baseline Newsletters