Comments
Richard Davies wrote: The UK has a good crop of technology pioneers in cloud computing - for example ElasticHosts, FlexiScale, Flexiant, OnApp - and also some strong government initiatives such as G-Cloud. We will have to see whether this kind of technical leadership converts into swift mass-market adoption or not.
Cloud Expo on Google News

SYS-CON.TV
Cloud Expo & Virtualization 2009 East
PLATINUM SPONSORS:
IBM
Smarter Business Solutions Through Dynamic Infrastructure
IBM
Smarter Insights: How the CIO Becomes a Hero Again
Microsoft
Windows Azure
GOLD SPONSORS:
Appsense
Why VDI?
CA
Maximizing the Business Value of Virtualization in Enterprise and Cloud Computing Environments
ExactTarget
Messaging in the Cloud - Email, SMS and Voice
Freedom OSS
Stairway to the Cloud
Sun
Sun's Incubation Platform: Helping Startups Serve the Enterprise
POWER PANELS:
Cloud Computing & Enterprise IT: Cost & Operational Benefits
How and Why is a Flexible IT Infrastructure the Key To the Future?
Click For 2008 West
Event Webcasts
Information Security & Law Enforcement Compared
With the growing encroachment of NAS, iSCSI, and FCoE on the realm of the SAN, this division is less clear

Since I first started covering storage, back around the turn of the century (sounds more impressive than it is, no?), the argument has been ongoing in far more organizations than you could imagine PoliceBadge about who should “own” storage security. Does it belong with the storage group? With the security group? How about in IT services, since they’re the ones that are on the pointy end of user relations?

Considering the number of times that the security group has been around this May-pole, you’d think they would have all the answers, but in many ways this isn’t a “what is best for our organization” type question, it’s largely a political one. After all, the key point is that the systems be locked down in the manner that the organization has chosen is best. Who does it really doesn’t matter one whit to the majority of your organization, they just want to assume that someone is. This can have negative impacts on the business if done wrong, and can open holes that malicious individuals both internal and external if not done at all.

Perhaps I’m too practical, perhaps each individual company that struggles with this problem has good reasons to. But in my opinion, pick a group, give them the responsibility, and move on. As long as someone is minding the store, the specific who is less important. Particularly with convergence of data and storage networks. When your SAN is an independent entity that is only exposed to the data network through machines with dedicated cards, then it makes a certain amount of sense to have that security rest with the storage staff, such as they may be. The machines will be locked down by corporate security policy like any other, and security for the SAN rests with those who are paid to know all about Storage Area Networks. Of course there’s some grey areas where the access level of a the interfacing machines has to mesh, but they’re teams working toward the same goal – providing secure and reliable infrastructure to the organization – so that bit of working together is not a huge problem. Or shouldn’t be anyway.

With the growing encroachment of NAS, iSCSI, and FCoE on the realm of the SAN, this division is less clear and that might be the source of the latest round of duck duck who’s responsible playing out in this space. Since convergence is happening and will continue to get stronger (seriously, only SAN-heads want two separate network technologies, everyone else could be convinced of the benefits of two separate networks, but not two separate network technologies), it does make sense to start transitioning this responsibility over to the security team. They’re responsible for keeping corporate data – all corporate data and systems – safe. Storage isn’t a special snowflake, it’s the holding point for all the stuff security is supposed to protect. So I think we’ve reached the point where they should.

If you’ve got a SAN, that’s going to mean training. If you have a ton of NAS’s, then it’s going to mean a headache for whomever is responsible. This is the part where I plug File Virtualization products like our ARX, which can aggregate security policy on your many NAS boxes into one centralized security model. That can include random shares Bob in Marketing created to show off his leet PowerPoint skills, or that Steve in AppDev created to show off his 1337 code h4x0r skills. It certainly makes security policy maintenance easier if you centralize it on such a device, and most security teams are familiar with Windows share security, making centralized NAS security not a far stretch. But even if you have decentralized NAS, policy is the same, it is merely implementation that is different, and even that might be the same, depending upon your architecture.

So what’s the point? Well, if you have a stretch of road that two counties claim ownership of, the correct solution is to have one patrol it while you figure out ownership. Remember that, because information security isn’t much different from law enforcement – an ounce of prevention and all.

Until next time,

Don.

Read the original blog entry...

About Don MacVittie

Don MacVittie is a Technical Marketing Manager at F5 Networks. In this role, he supports outbound marketing, education, and evangelism efforts around development, storage, and IT management topics related to F5 solutions. His role includes authoring technical materials, participating in social and community-based forums, and providing guidance for the development of marketing resources. As an industry veteran, MacVittie has extensive programming experience along with project management, IT management, and systems/network administration expertise.

Prior to joining F5, MacVittie was a Senior Technology Editor at Network Computing, where he conducted product research and evaluated storage and server systems, as well as development and outsourcing solutions. He has authored numerous articles on a variety of topics aimed at IT professionals. MacVittie holds a B.S. in Computer Science from Northern Michigan University, and an M.S. in Computer Science from Nova Southeastern University.



Latest Cloud Developer Stories
As a result, it said, of “customer feedback and evolving usage patterns,” Microsoft cut the price of its cloud-ified SQL Azure database 48%–75% for databases larger than 1GB and introduced a new entry-level 100MB model. It blogged that it’s noticed that many projects start smal...
Wide and cheap availability of cloud-based media services is upon us. With the transformations these services are already bringing to the consumption of music, video and interactive media, change has likewise come to professional workflows. Documents in 2012 are read, written, co...
With Cloud Expo 2012 New York (10th Cloud Expo) just four months away, what better time to start introducing you in greater detail to the distinguished individuals in our incredible Speaker Faculty for the technical and strategy sessions at the conference... We have technical ...
Fresh off a happy quarter, Rackspace said Thursday that it’s bought SharePoint911, one of those you-never-heard-of-them outfits that does SharePoint consulting, training and JumpStart services so it can deliver newfangled SharePoint services along with its existing SharePoint hos...
Cloud is a shift from the focus on underlying technology implementation to leveraging existing implementations and further building upon them. Cloud orchestration or a network of clouds is the wave of the future where these clouds can operate with elasticity, scalability, and eff...
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

SYS-CON Featured Whitepapers
ADS BY GOOGLE