Commentary

Howard Marks
 

Learn From Other's Mistakes - Encrypt Your Tapes

In the most recent of what seems to be an endless litany of mistakes by people who should know better Bank of New York Mellon has used a third party carrier to transport data tapes from one of their sites to another and as Gomer Pyle would say "surprise, surprise" the courier lost the package. Twice. On February 27th they lost a box of tapes with data on over 4 million customers, on April 29 they lost another tape. In addition to responding with the usual, patently untrue, platitude "Protecting the confidentiality of our clients' information has long been a top priority at The Bank of New York Mellon" the bank is on the hook for 2 years of credit report monitoring and $25,000 in identity theft insurance for the customers placed at risk.

In the most recent of what seems to be an endless litany of mistakes by people who should know better Bank of New York Mellon has used a third party carrier to transport data tapes from one of their sites to another and as Gomer Pyle would say "surprise, surprise" the courier lost the package. Twice. On February 27th they lost a box of tapes with data on over 4 million customers, on April 29 they lost another tape. In addition to responding with the usual, patently untrue, platitude "Protecting the confidentiality of our clients' information has long been a top priority at The Bank of New York Mellon" the bank is on the hook for 2 years of credit report monitoring and $25,000 in identity theft insurance for the customers placed at risk.Why would an organization like BoNY ship unencrypted tapes in this day and age? After all you can encrypt tapes using any of the major backup programs, hardware encryption appliances from NetApp/Decru on your Fibre Channel SAN or using the built in encryption in today's LTO-4 or high end tape drives from SUN and IBM. Even workgroup backup software like Backup Exec can encrypt your tapes. Surely a big outfit like BoNY can update their backup software to versions released since 2006 to get this valuable feature.

The answer is key management, or more accurately trying to perfect key management. I'm sure there's a multidisciplinary task force at BoNY that's spent the past 3 years working on defining the bank's encryption and key management requirements. Someday they'll even start looking for solutions.


More Storage Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

Don't let this happen to you. Encrypting tapes in flight doesn't require complex key management. Encrypt ALL your tapes with the same key. Save the key in SEVERAL places, on USB flash keys if possible, so you can restore when your primary media server needs to be rebuilt.

Figure out how to manage ALL your keys so you can have keys automatically be deleted when tapes expire and use different keys for different types of data later. After all you didn't wait for global key management before you set up a VPN did you?


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links