Tuesday, November 17, 2009

Are you protecting your Data?

The job of storage engineer is not only to keep the data on the storage; also they have the responsible to keep the data safe. Here are some of the tips how the data can be maintained safely.
For any Institute or any organization even it’s small or big, Data is the most important asset for them. Of course loosing data means there would be a big financial loss to the organizations. So how the plan for the Data security should be? Data security means protecting the data from corruption, unauthorized access and modification & deletion. When looking into the data access there are many internal & external threats to the data. Most common factors causing the data damage would be virus attacks, unauthorized access, unplanned data deletion, natural disaster, spyware, malware, hackers attack or any other threats comes from malicious sites the systems are connected on internet.

To keep the data safe what are the necessary steps to be taken care of?

• First and the foremost thing is the Backup. Taking regular backup of important data using backup software and saving them on tape libraries using multiple backup windows (either incremental or differential)

• Try to avoid giving internet access to the Storage nodes. There is a chance of dangerous threats, viruses & hackers comes in

• Giving access to the Storage data only based on users or groups who needs rights. Try to avoid keeping open access for everyone. This may lead to unauthorized access and possibility of accidental data deletion

• Disaster recovery policy needs to be set by keeping the data either in hard disks or on tapes at multiple locations. This saves the data even at the natural disaster times

• Create the proper work flow for every process & projects and make sure only authorized users are accessing the data

• Keep the patches updated on the operating systems

• Having access control to the data center prevents unauthorized person entering to it

• Keep safe your wireless access

• Update the inventory sheets and maintain the data locations regularly

• Keep the anti virus application updated on all the systems & servers

• Having a firewall inside the organization helps to prevent attacks from hackers

• Keep the spyware applications updated

• When there is a need of sending the data to other geographical locations using the FTP method, make sure the data is encrypted

• Network monitoring program should be there in every organization & needs to be monitored from time to time to check the activities of the users accessing the network

• Passwords are the key criteria for the access to the critical servers and storage. So keep the passwords strong and as well as secret & never share with any outside person who are not as part of the business

• Monitor the activities happens on the mail server. Maintain quota limitation on mail box sizes & restriction policies on file extensions

Main thing to be focused on :-

Each and every employee in the organization needs to be given training on data security & they should be aware of all the security threats. Stick a Do's & Dont's sheets on all the employees desk to make them aware of their responsibilities on data security.