Chapter 10—Encryption and Key Management BlueScale Key Management
August 2017 User Guide—Spectra T50e Library
301
Medium Security Site
Thefollowingtabledescribesthesecurityconsiderationsandthesuggested
encryptionconfigurationforamedium‐sizedorganizationwith
250employees.
Security
Considerations
Strategy
Securitygoals Protectingcompanyfromlegalliabilityassociatedwithunauthorizedaccessto
datastoredontapeonsiteandoffsite,includingtransporttotheoffsitelocation.
Encryption
principals
ITseniorstaff,chiefoperatingofficer.
Datatoencrypt Intellectualproperty,financial,customer,andinventorydata.
Levelofsecurityto
implement
BlueScaleProfessionalEdition,withmultiplekeys
Standardinitializationmode:encryptionpartitionsenabledatstart‐up
Multi‐usermode,withthreeencryptionpasswords
Datasetsrequiring
isolationfromother
encrypteddata
Separatepartitionsandkeysforthesedatasets:financialdata,inventorydata,
customerdata,andintellectualpropertydata.Withthisrequirement,thesite
mustuseaminimumoffourencryption‐enabledpartitions,alongwith
partition(s)fornon‐encrypteddata.
Keyescrow
method
Storekeycopieswithcorporatelegalcounselandapaid,trusted,third‐party
escrowservice.
Numberofcopies
ofeachkeytostore,
andlocations
Keepthreecopiesofeachkey:storeonewithcorporatelegalcounsel,twowith
thekeyescrowservice.
Keyrotationplan Createanewkeyeveryquarterforeachpartitiondedicatedtoencryption.
Trackingkey
monikers,exported
keypasswords,and
passwordtopermit
accessto
encryptionfeatures
Sendtokeyescrowserviceanencrypteddocumentthatincludesthepassword
usedtoaccessencryptionfeatures,superuserpassword,andallpasswords
necessarytoimportencryptionkeys.Thisfilecannotbecreatedorstoredona
networkedcomputer.Deletethefilefromthecomputerafterthedocumentor
fileistransmitted
securelytothekeyescrowservice.
Multiple
encryptionteams
(optional)
ThreeITadministrators,alongwiththeseniorITadminandtheCOO.
Scheduleandrun
drills
Annualevaluationandreview,alongwithwidercorporatesecurityplan.
Passwords Passwordstoaccessencryptionfeatures:minimumof12characters,
includingatleastonenumberandoneletter
Passwordtoexportandimportencryptionkeys:minimumof30characters,
includingatleastonenumberandoneletter