drj logo
drj logo

Welcome to DRJ

Already registered user? Please login here

Create new account
(it's completely free). Subscribe

x

Secure Disaster Recovery Starts with a Strong Backup Environment

Business Continuity ManagementCyber Resilience & IT Disaster RecoveryData Protection: Backup & Recovery

No one in IT leadership wants to go through a data disaster recovery effort or rectify large-scale impacts to corporate systems. Even so, it’s something CIOs, CISOs, data administrators, and others in charge of enterprise data infrastructure have found themselves doing thanks to the increasing frequency of ransomware attacks and other cybersecurity incidents. (See Colonial Pipeline, Brenntag, Accenture, South African Justice Department. The list goes on.) These cyberattack threats are in addition to the increase in wildfires, storms, and other natural disasters which threaten physical data center infrastructures.

The best way to recover quickly from a disaster — or even avoid it altogether — is to make sure your organization is following a comprehensive data resiliency plan. Make sure you have your house in order when it comes to audits, compliance mandates, data retention policies, and data governance. All those secure data requirements must be covered in the backup environment.

Compliance Mandates

Data breaches can come at an enormous cost: lost business continuity, loss of reputation and customer confidence, and time and resources required to recover. With new threats emerging every day, the risk of not securing files is greater than ever. Data can be a tremendous asset, but it can also be a tremendous liability if it is not managed according to a set of common policies. This means it cannot be managed only by your own internal governance policies, but it must include at least one governmental data security mandate. Some of the major ones include the following:

Violating these compliance mandates can have severe consequences. That’s why almost 70% of all companies now see audit verification and compliance mandates as a major driver for corporate spending. Forbes estimates major U.S. and U.K. businesses have spent a whopping $9 billion in preparation for GDPR compliance. Even with all that spending, many companies are struggling with compliance and with fully protecting sensitive data.

Managing constantly evolving standards is a feat most organizations do not have the skills or resources to do right. Having a backup solution in place with built-in features which ensure security best practices and compliance becomes a critical component of your data center and makes it no longer a “nice-to-have” option.

Features of solutions which enable data compliance management include the following:

  • Customer-controlled security certificates.
  • Comprehensive audit trails to support governance.
  • Audit exception handling triggers notification and review process.
  • Two-factor authentication.
  • End-to-end encryption.
  • Data protection in transport, at rest, and at source.
  • Customer-managed policy creation and provable policy enforcement.

Audit Readiness

Since most businesses must adhere to at least one set of IT compliance requirements, IT compliance audits are inevitable. Therefore, you must be able to track and demonstrate the current and past state of all operations and events to prove compliance with all cybersecurity and data protection regulations — not only to pass your audits but to completely protect data for the business.

Failed audits can bring stiff penalties. For example, a compliance failure with FISMA could result in loss of federal funding, government hearings, increased government oversight, and prohibition from future government contracts, depending on the severity of the violation. Failing a SOX audit can lead to fines, removal from public stock exchanges, and invalidation of directors and officers (D&O) insurance policies, not to mention jail time for CEOs and CFOs who knowingly submit incorrect certifications.

If you couldn’t pass an audit today, then your data isn’t secure

A lack of tracking and auditing capabilities creates a significant security risk that puts the whole organization in jeopardy.

If you cannot clearly and quickly see what is happening in every corner of your data protection landscape, then there is a good chance you are missing something. A failed audit indicates holes in the security infrastructure that could lead to:

  • Ransomware attacks.
  • Company data breaches.
  • Operational shutdowns.
  • Harm to your company’s customers.
  • Loss of reputation.

Any one of these risks could significantly damage the business.

How to plug security holes and be ready for an audit

Visibility and audit readiness should be key security components of any data protection solution. Audit readiness for backup includes several capabilities:

  • Visibility into the entire environment.
  • Tracking of all operations, events, and players.
  • Ability to report on and prove what’s happened in your backup environment.
  • Compliance monitoring for all backup components and data.
  • Analysis of unusual activity and alerting for suspected events.

When your backup software and infrastructure do not address the need for visibility, then you’re left to manage any internal or external audit requests manually. This approach is resource-intensive and often incomplete. Look for a backup provider that offers comprehensive and continuous audit readiness across backup infrastructure, data, and operations as part of the core features.

Data Retention Policies

In simple terms, data retention is the practice of storing and managing data and records for a specified period. A data retention policy defines an organization’s system of rules for the types of data to be stored, and for how long.

Policies are usually built around operational and regulatory requirements, such as a need to maintain accurate financial records, comply with laws and industry regulations, or make sure data is easy to access for e-discovery and litigation purposes. A well-designed data retention policy should cover all the different types of information the organization handles, together with rules for where — and for how long — each type should be stored and who should have access to data to recover it.

It might seem fundamental, but data retention is something that many organizations struggle with, primarily because they lack a data protection environment that can simplify policy definition, management, and enforcement. For example, many organizations match their retention policy to the amount of space they have in a single specified disk array. This is an unfortunately short-sighted policy – as the volume of backed-up data grows; the retention length is forced to become shorter and shorter in order not to create backup failures by filling the available space. With the pressures on IT teams, however, it is easy to understand why an organization is forced to take this kind of risky approach. Without the right tools, it can be exceedingly difficult to manage data retention with consistency, resulting in excessive time spent managing backups, increased time to recover data, and, in the worst case, inability to effectively recover data at all.

To manage policies effectively and consistently despite ever-evolving requirements, implement a backup solution that gives you command over your data with comprehensive policy management — so you can set up protection how, when, and where it’s needed. Look for a solution with two key capabilities which make it easy to configure and manage data retention policies:

  • Long-term retention and tape integration, with the ability to use cloud storage, tape integration, third-party licensing options, and more.
  • Retention policies for two-site replication delivered to meet your business’ unique recovery requirements.

Data Governance

Just like how your company needs processes, policies, and standards to make it run in an orderly, secure, and compliant fashion, the same is true for your data. It is called data governance — the responsible management of data throughout its lifecycle. It is about applying data discipline to every aspect and process around data ... and being able to demonstrate that that data discipline was enforced.

Data governance is about being a good steward over your data during its entire lifecycle, from its creation or acceptance to its deletion.

The components of data governance include:

  • Data integrity – As data is accessed, transferred, stored, or otherwise used, you must ensure that it has not been changed. Cyclic redundancy checks (CRCs) and checksums are proven techniques for guaranteeing data integrity in some backup, storage, and networking products.
  • Data and metadata immutability – Similar to data integrity, data immutability is about ensuring that data cannot be changed. Data immutability is an important security characteristic of some storage products. It is also important to note that data often has associated metadata that is essential for use of that data (e.g., inode information for Unix file systems or a backup catalog for backup data). This metadata also needs to be protected. If data is immutable but its associated metadata is lost, the immutable data might become useless. For example, a company with immutable backup storage recently lost all its backups when a hacker destroyed the backup metadata catalog that was necessary to access that backup data.
  • Data protection and security – Companies should create copies (including off-site copies) of valuable data in case the data is damaged or destroyed. In addition, data must be secured against unauthorized viewing or access. Data security includes the ability to encrypt data when in flight or at rest.
  • Data access controls – Access to data should be restricted only to those users or processes with a business need. And those with a valid business requirement for access must be properly authenticated.
  • Enforceable policy management – Business policies for managing data must be established and enforced consistently.
  • Enforceable data locality – There are many regulations, such as the European Union’s General Data Protection Regulation (GDPR), that require controls and enforcement of where data may reside geographically or politically.
  • Comprehensive auditing – Even for businesses that are implementing some of the data governance disciplines above, being able to document and prove it for data is a huge added challenge.

Choose the right tools and strategy to achieve comprehensive data protection and data governance for your entire backup landscape and operations. Look for a solution that incorporates all the components above and automatically enforce your retention policies from the moment data enters the system to when it is deleted.

Conclusion

Secure, auditable, policy-driven backup operations are the first line of defense in the battle against a data loss disaster — and give you the best chance for a quick, seamless recovery when calamity strikes. Equipping your team and business with the right tools, including the right backup solution, can make disasters an impossibility in the first place.

ABOUT THE AUTHOR

Chris Snell

Chris Snell has more than 20 years of experience in storage, backup and disaster recovery, and virtualization, working with organizations to design solutions that ensure their corporate data is protected and ready for recovery. Snell is most at-home at disruptive start-ups, where he can exercise his passion for delivering ground-breaking, high-value technologies to the IT market. Today, he serves as the lead Cobalt Iron solution architect for the EMEA region.

Latest News
DRJ HOT ITEMS
Webinar Spotlight
Fetching Upcoming Webinars...
Journal Categories

AI: Automation & Innovation

Business Continuity Management

Crisis Management & Emergency Response

Cyber Resilience & IT Disaster Recovery

Leadership: Culture & Workforce Resilience

Operational Resilience

Risk Management & Quantification

Sector-Specific & Critical Infrastructure Resilience

Supply Chain & Third-Party Resilience

Governance: Compliance & Regulatory Readiness

Incident Management & Response Coordination

Resilience Strategy & Program Maturity

Data Protection: Backup & Recovery

Exercises: Testing & Scenario Planning

Emerging Threats: Geopolitical & Climate Risk

Contact Us

Newsletter

The Journal, right in your inbox.