Chapter 10—Encryption and Key Management BlueScale Key Management
August 2017 User Guide—Spectra T50e Library
300
Site Security Examples
Thefollowingsectionsprovideexamplesofdifferentsecurityscenarios.
Low Security Site
Thefollowingtabledescribesthesecurityconsiderationsandthesuggested
encryptionconfigurationforasmallcompanywith75employ ees.
Security
Consideration
Strategy
Securitygoals Protectingcompanyfromlegalliabilityassociatedwithunauthorizedaccessto
datastoredontape,bothonsiteandoffsite,includingtransporttotheoffsite
location.
Encryption
principals
ITadministrator,companypresident,corporatelegalcounsel.
Datatoencrypt Financialandconsumeridentitydata.
Levelofsecurityto
implement
BlueScaleStandardEdition:singlekeyperlibraryissufficient.
Standardinitializationmode:encryptionpartitionsenabledatstart‐up.
Datasetsrequiring
isolation
None.Asinglepartitionforencrypteddataissufficient.
Keyescrow
method
Staffatcompanyescrowkeysatasiteremotefromthedatastoragelocation.
Copiesofeachkey
tostoreandtheir
locations
Keepthreecopiesofeachkey:onewiththeseniorITadministrator,onewith
thecompanypresident,oneinacorporatesafetydepositbox.
Keyrotationplan Createanewkeyeverysixmonths.
Trackingkey
monikersand
passwords
Onanon‐networkedcomputerthatsupportsencryption,createoneormore
chartsorlistswiththisdata,includingkeymonikers,datesused,encryption
andsuperuserpasswords,andpasswordsusedtoencryptexportedkeys.For
additionalsecurity,youmaywanttoavoidtrackingtherelationshipbetween
monikersandtheencryptedcartridges.
Thelibrarypromptsfortherequired
monikerwhenyourestoreencrypteddatafromacartridge.
Multiple
encryptionteams
(optional)
Configureaseparatesetofuserswhoareresponsibleformanagingencrypted
data.Theseusersmaybethesameasthoseidentifiedastheencryption
principals.
Decryptand
restoreencrypted
data
Regularlyreviewdataencryptionanddecryptionprocedurestomakesurethat
backupsandrestoresareworkingproperly.Runteststoensurethatencrypted
datacanbedecryptedandrestoredwhenneeded.
Passwords Requirepasswordswithaminimumof12characters,includingatleastone
numberandoneletter,toaccesstheencryptionfeatures.
Requirepasswordswithaminimumof30characters,includingatleastone
numberandoneletter,toexportandimportencryptionkeys.