EasyManua.ls Logo

Spectra T50e - Page 304

Default Icon
539 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Chapter 10—Encryption and Key Management BlueScale Key Management
August 2017 User GuideSpectra T50e Library
301
Medium Security Site
Thefollowingtabledescribesthesecurityconsiderationsandthesuggested
encryptionconfigurationforamediumsizedorganizationwith
250employees.
Security
Considerations
Strategy
Securitygoals Protectingcompanyfromlegalliabilityassociatedwithunauthorizedaccessto
datastoredontapeonsiteandoffsite,includingtransporttotheoffsitelocation.
Encryption
principals
ITseniorstaff,chiefoperatingofficer.
Datatoencrypt Intellectualproperty,financial,customer,andinventorydata.
Levelofsecurityto
implement
BlueScaleProfessionalEdition,withmultiplekeys
Standardinitializationmode:encryptionpartitionsenabledatstartup
Multiusermode,withthreeencryptionpasswords
Datasetsrequiring
isolationfromother
encrypteddata
Separatepartitionsandkeysforthesedatasets:financialdata,inventorydata,
customerdata,andintellectualpropertydata.Withthisrequirement,thesite
mustuseaminimumoffourencryptionenabledpartitions,alongwith
partition(s)fornonencrypteddata.
Keyescrow
method
Storekeycopieswithcorporatelegalcounselandapaid,trusted,thirdparty
escrowservice.
Numberofcopies
ofeachkeytostore,
andlocations
Keepthreecopiesofeachkey:storeonewithcorporatelegalcounsel,twowith
thekeyescrowservice.
Keyrotationplan Createanewkeyeveryquarterforeachpartitiondedicatedtoencryption.
Trackingkey
monikers,exported
keypasswords,and
passwordtopermit
accessto
encryptionfeatures
Sendtokeyescrowserviceanencrypteddocumentthatincludesthepassword
usedtoaccessencryptionfeatures,superuserpassword,andallpasswords
necessarytoimportencryptionkeys.Thisfilecannotbecreatedorstoredona
networkedcomputer.Deletethefilefromthecomputerafterthedocumentor
fileistransmitted
securelytothekeyescrowservice.
Multiple
encryptionteams
(optional)
ThreeITadministrators,alongwiththeseniorITadminandtheCOO.
Scheduleandrun
drills
Annualevaluationandreview,alongwithwidercorporatesecurityplan.
Passwords Passwordstoaccessencryptionfeatures:minimumof12characters,
includingatleastonenumberandoneletter
Passwordtoexportandimportencryptionkeys:minimumof30characters,
includingatleastonenumberandoneletter

Table of Contents

Other manuals for Spectra T50e

Related product manuals