Book description
Storage systems must provide reliable and convenient data access to all authorized users while simultaneously preventing threats coming from outside or even inside the enterprise.
Security threats come in many forms, from unauthorized access to data, data tampering, denial of service, and obtaining privileged access to systems.
According to the Storage Network Industry Association (SNIA), data security in the context of storage systems is responsible for safeguarding the data against theft, prevention of unauthorized disclosure of data, prevention of data tampering, and accidental corruption. This process ensures accountability, authenticity, business continuity, and regulatory compliance.
Security for storage systems can be classified as follows:
- Data storage (data at rest, which includes data durability and immutability)
- Access to data
- Movement of data (data in flight)
- Management of data
- Security of data in transit
- Security of data at rest
- Authentication
- Authorization
- Hadoop security
- Immutability
- Secure administration
- Audit logging
- Security for transparent cloud tiering (TCT)
- Security for OpenStack drivers
Unless stated otherwise, the functions that are mentioned in this paper are available in IBM Spectrum Scale V4.2.1 or later releases.
IBM® Spectrum Scale is a software-defined storage system for high performance, large-scale workloads on-premises or in the cloud.IBM Spectrum™ Scale addresses all four aspects of security by securing data at rest (protecting data at rest with snapshots, and backups and immutability features) and securing data in flight (providing secure management of data, and secure access to data by using authentication and authorization across multiple supported access protocols). These protocols include POSIX, NFS, SMB, Hadoop, and Object (REST). For automated data management, it is equipped with powerful information lifecycle management (ILM) tools that can help administer unstructured data by providing the correct security for the correct data.
This IBM Redpaper™ publication details the various aspects of security in IBM Spectrum Scale™, including the following items:
- Security of data in transit
Table of contents
- Front cover
- Notices
- Preface
- Chapter 1. Secure data in transit
- Chapter 2. Secure data at rest
- Chapter 3. Authentication
- Chapter 4. Authorizing protocol users
- Chapter 5. Secure administration
- Chapter 6. Immutability
- Chapter 7. Audit logging
- Chapter 8. Hadoop security
-
Chapter 9. Security for transparent cloud tiering
- 9.1 Securing data in flight and at rest
- 9.2 Securing the keys that are used to protect the data
- 9.3 Configuring transparent cloud tiering with an external key manager: IBM Security Key Lifecycle Manager
- 9.4 Configuring transparent cloud tiering with local key manager: Java Key Store
- 9.5 TCT client-server communication security
- 9.6 Security of TCT commands
- 9.7 Data integrity protection
- 9.8 Security considerations while configuring a cloud object storage
- 9.9 References
- Chapter 10. Security for OpenStack drivers
- Chapter 11. Security for AFM
-
Chapter 12. Firewall recommendations
- 12.1 Types of networks
- 12.2 IBM Spectrum Scale installation and basic cluster operation
- 12.3 GUI
- 12.4 Performance Monitoring tools
- 12.5 Transparent cloud tiering
- 12.6 Cluster Export Services
- 12.7 File audit logging
- 12.8 Active File Management
- 12.9 IBM Spectrum Scale remote mounting of file systems
- 12.10 IBM Spectrum Protect connectivity by using mmbackup and HSM
- 12.11 IBM Spectrum Archive connectivity
- 12.12 IBM Spectrum Control connectivity
- 12.13 Key server ports
- 12.14 References
- Appendix A. Examples of how to open firewall ports
- Glossary
- Related publications
- Back cover
Product information
- Title: IBM Spectrum Scale Security
- Author(s):
- Release date: September 2018
- Publisher(s): IBM Redbooks
- ISBN: 9780738457161
You might also like
book
Cyber Resiliency Solution for IBM Spectrum Scale
This document is intended to facilitate the deployment of the Cyber Resiliency solution for IBM® Spectrum …
book
IBM Power Systems Virtual Server Guide for IBM i
This IBM® Redbooks® publication delivers a how-to usage content perspective that describes deployment, networking, and data …
book
IBM Spectrum Scale (formerly GPFS)
This IBM® Redbooks® publication updates and complements the previous publication: Implementing the IBM General Parallel File …
book
Integration of IBM Aspera Sync with IBM Spectrum Scale: Protecting and Sharing Files Globally
Economic globalization requires data to be available globally. With most data stored in file systems, solutions …