Home > Data Backup Tips > Backup and recovery > Secure your data backups with encryption key management best practices
Data Backup Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

BACKUP AND RECOVERY

Secure your data backups with encryption key management best practices


Kevin Beaver
10.26.2009
Rating: -3.50- (out of 5)


News and trends in the storage industry
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Ending up as a data breach statistic is not likely in your organization's long-term goals. To resolve this issue, you can encrypt your backups and mobile storage media. Your backups will be secure and exempt from the breach notification requirements many of the information security regulations mandate -- until a vulnerability in your encryption key management practices is exploited. Sloppy key management practices are a surefire way to negate most, if not all, of the benefits of encrypting data at rest and land your business in a real bind.

More on data backup security
Secure data destruction options for old backup tapes and disk

How do you make sure your data is secure when using a online/cloud backup provider?

Using an encryption appliance for data backup security
Regardless of the size of your organization, here are several essential key management best practices you need to know about to maximize your investment in encryption and minimize your business risks:

Key management requires upfront planning and ongoing administration. Make sure you have the resources in place for key issuance/renewal/revocation, setting and enforcing policies, system maintenance and monitoring, and so on -- across all of your backup systems.

Work with your existing data backup/storage/security vendors or seek out new ones to help with your implementation. Generic enterprise key management solutions from NetApp Inc., RSA (the security division of EMC Corp.), Thales and Venafi Inc. may offer what you need. If you just want key management at the backup/storage level, then you may want to look at more niche products such as Hewlett-Packard (HP) Co. StorageWorks Secure Key Manager and 10Zig Technology's Q3e encryption appliance or its Q3i tape drive with encryption, as well as some more mainstream IBM Corp. and Sun Microsystems Inc. StorageTek drives. You may have to go with multiple vendors for key management depending on your approach.

Your key management initiatives need to be an all-or-nothing approach, at least to the extent that you know exactly what's where. Encrypting some data at rest and not other data without understanding the specific types of data in each location can be dangerous. All it takes is one lost backup tape that "didn't need encryption since it stored nothing of value" to create a big problem.

Utilize the principle of separation of duties. I know, it's one of those security "best practices" that everyone preaches but is often hard to implement, but you still need to strive for it. Having more than one person storing, backing up, referencing and rotating encryption keys is essential. As part of this process, be sure to define the roles of the key players to make sure everyone's on the same page. And make your key management policy a written one that's stored and made readily accessible to everyone on an intranet site.

Never assume that encrypted means secure. There's always the possibility that a third party may gain access to your media and somehow recover your encryption keys. Know what the vulnerabilities are in your environment. If it makes sense because of added physical vulnerabilities or other risks, consider utilizing secondary hardware keys if they're available. This requires both the original backup hardware and the hardware key to decipher the backups adding yet another layer of security. Certain types of businesses where this may be easily justified include banking, education, and healthcare.

Like many things security-related, key management is still relatively immature. The good news is that there are industry bodies such as OASIS EKMI, NIST, and the IEEE looking to simplify things and bring interoperability to the industry.

About the author: Kevin Beaver is an information security consultant, speaker, and expert witness with Atlanta-based Principle Logic, LLC. Having worked for himself over the past seven years, Kevin specializes in performing independent security assessments and helping IT professionals enhance their careers through his Security On Wheels information security audio books and blog.

Rate this Tip
To rate tips, you must be a member of SearchDataBackup.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Backup and recovery
Criteria for choosing the right tape encryption solution for your data backup plan
Creating a System Recovery Disk in Windows 7: A step-by-step tutorial
Modern data backup and recovery system considerations
SQL Server data backup and recovery best practices
Using data deduplication with backup applications: Source vs. target dedupe
Data backup for virtual machines: Alternative methods to VMware Consolidated Backup
Upgrading from LTO-3 to LTO-4 tape for data backup and recovery
Is VMware Consolidated Backup right for your enterprise?
Is cloud data backup service right for your organization?
Are data backup vendor certifications valuable for backup administrators?

Data backup security
Criteria for choosing the right tape encryption solution for your data backup plan
Data backup and recovery news briefs: Thales Group releases CryptoStor Tape 3.0 appliance
Podcast: Backing up data on mobile devices
Secure data destruction options for old backup tapes and disk
Putting a solid data backup and recovery plan behind mobile devices
Data storage backup security tutorial: Tape encryption and cloud backup
Quantum adds VMware data backup, encryption key management device
How do you make sure your data is secure when using a online/cloud backup provider?
Using an encryption appliance for data backup security
LTO-4 tape technology finally catching on -- tape storage isn't dead yet

Tape backup and tape libraries
Texas Tech turns to data deduplication for data backup, disaster recovery
Data backup and recovery news briefs: Rackspace unveils cloud-based file storage apps
Spectra Logic looks to leapfrog high-end tape storage market with T-Finity tape library
Data backup news briefs: ProStor Systems ships InfiniVault removable disk backup appliance for SMBs
Upgrading from LTO-3 to LTO-4 tape for data backup and recovery
W. Curtis Preston: Articles and podcasts on data backup and recovery
The tape storage end game: The pros and cons of recycling backup tapes
Data backup and recovery news briefs: Tandberg Data introduces DAT tape drives and media
Community Health Centers Alliance takes control of data backup and recovery
Sun Microsystems wins best tape library in Storage Quality Awards survey

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Enterprise Backup Solutions - Continuous Data Protection (CDP)
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts