Commentary

Learn From Other's Mistakes - Encrypt Your Tapes

Howard Marks
Network Computing Blogger

In the most recent of what seems to be an endless litany of mistakes by people who should know better Bank of New York Mellon has used a third party carrier to transport data tapes from one of their sites to another and as Gomer Pyle would say "surprise, surprise" the courier lost the package. Twice. On February 27th they lost a box of tapes with data on over 4 million customers, on April 29 they lost another tape. In addition to responding with the usual, patently untrue, platitude "Protecting the confidentiality of our clients' information has long been a top priority at The Bank of New York Mellon" the bank is on the hook for 2 years of credit report monitoring and $25,000 in identity theft insurance for the customers placed at risk.

In the most recent of what seems to be an endless litany of mistakes by people who should know better Bank of New York Mellon has used a third party carrier to transport data tapes from one of their sites to another and as Gomer Pyle would say "surprise, surprise" the courier lost the package. Twice. On February 27th they lost a box of tapes with data on over 4 million customers, on April 29 they lost another tape. In addition to responding with the usual, patently untrue, platitude "Protecting the confidentiality of our clients' information has long been a top priority at The Bank of New York Mellon" the bank is on the hook for 2 years of credit report monitoring and $25,000 in identity theft insurance for the customers placed at risk.Why would an organization like BoNY ship unencrypted tapes in this day and age? After all you can encrypt tapes using any of the major backup programs, hardware encryption appliances from NetApp/Decru on your Fibre Channel SAN or using the built in encryption in today's LTO-4 or high end tape drives from SUN and IBM. Even workgroup backup software like Backup Exec can encrypt your tapes. Surely a big outfit like BoNY can update their backup software to versions released since 2006 to get this valuable feature.

The answer is key management, or more accurately trying to perfect key management. I'm sure there's a multidisciplinary task force at BoNY that's spent the past 3 years working on defining the bank's encryption and key management requirements. Someday they'll even start looking for solutions.


More Storage Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

Don't let this happen to you. Encrypting tapes in flight doesn't require complex key management. Encrypt ALL your tapes with the same key. Save the key in SEVERAL places, on USB flash keys if possible, so you can restore when your primary media server needs to be rebuilt.

Figure out how to manage ALL your keys so you can have keys automatically be deleted when tapes expire and use different keys for different types of data later. After all you didn't wait for global key management before you set up a VPN did you?

Related Reading


Informationweek Discussions

Start the Discussion


InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS

Resource Links