ISO/IEC 27040

ISO/IEC 27040[1] is part of a growing family of International Standards published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) in the area of security techniques; the standard is being developed by Subcommitee 27 (SC27) - IT Security techniques of the first Joint Technical Committee 1 (JTC 1) of the ISO/IEC. A major element of SC27's program of work includes International Standards for information security management systems (ISMS), often referred to as the 'ISO/IEC 27000-series'.

The full title of ISO/IEC 27040 is Information technology — Security techniques — Storage security (ISO/IEC 27040:2015)

Overview and introduction

The purpose of ISO/IEC 27040 is to provide security guidance for storage systems and ecosystems as well as for protection of data in these systems. It supports the general concepts specified in ISO/IEC 27001.

This International Standard is relevant to managers and staff concerned with information security risk management within an organization and, where appropriate, external parties supporting such activities. The objectives for this International Standard are to:

  • publicizing the risks,
  • assist organizations in better securing their data,
  • provide a basis for designing and auditing storage security controls.

ISO/IEC 27040 provides specific, detailed implementation guidance relevant to storage security for the general security controls described in ISO/IEC 27002.

This International Standard is not a reference or normative document for regulatory and legislative security requirements as they vary by country.

History

Work commenced on ISO/IEC 27040 in the fall of 2010, following the SC27 meeting in Redmond, WA. The project was placed on the extended timeline, allowing up to 48 months to develop the standard rather than the normal 36 months. The ISO/IEC 27040 standard was published on January 5, 2015.

Throughout the development of ISO/IEC 27040, organizations such as the Storage Networking Industry Association (SNIA) with its Storage Security Best Current Practices (BCPs),[2][3] the Trusted Computing Group's (TCG) Storage Working Group with its work on self-encrypting drives, and INCITS' storage-oriented Technical Committees (T10, T11, and T13) provided important comments[who?] and contributions.

Eric Hibbard served as the ISO Editor throughout the development of ISO/IEC 27040.

Structure of the standard

27040:2015 has seven short clauses and three annexes, which cover:

1. Scope of the standard
2. A list of other standards that are indispensable to understanding and using ISO/IEC 27040
3. Terminology that is either imported from other standards or defined in this standard
4. A list of used abbreviations and acronyms used in the standard
5. An overview of key storage and storage security concepts as well as information on the associated risks
6. Describes the controls that support storage security technical architectures, including Direct Attached Storage (DAS), storage networking, storage management, block-based storage, file-based storage, object-based storage, and security services.
7. Provides guidelines for the design and implementation of storage security (e.g., design principles; data reliability, availability, and resilience; data retention; data confidentiality and integrity; visualization; and design and implementation considerations)
Annex A. Media-specific guidance for sanitization, including cryptographic erase (parallels NIST SP 800-88r1)
Annex B. Tables for selecting appropriate security controls based on data sensitivity or security priorities (confidentiality, integrity, or availability)
Annex C. Descriptions of important security and storage concepts (mini-tutorials)
Bibliography. A list of standards and specifications that had an influence on materials in ISO/IEC 27040

The bibliography is one of the more comprehensive lists of references on storage security.

Supporting controls for storage security

A major element of the ISO/IEC 27040 standard is focused on the identification of security controls for different types of storage systems and architectures, including the following:

  • Recommendations to help secure Direct Attached Storage (DAS)
  • Broad coverage of security for storage networking technologies and topologies with an emphasis on Storage Area Networks or SAN (e.g., Fibre Channel, iSCSI, FCoE, etc.) and Network Attached Storage or NAS (e.g., NFS and SMB/CIFS)
  • Identifying important security issues and guidance for storage management
  • Security for block-based storage systems with Fibre Channel and IP interfaces (above and beyond the storage networking materials)
  • Security for file-based storage systems with NFS, SMB/CIFS, and pNFS interfaces (above and beyond the storage networking materials)
  • Security for cloud storage, object-based storage (OSD) and Content Addressable Storage (CAS)
  • Recommendations for storage security services (sanitization, data confidentiality, and data reductions)

Design and implementation guidance for storage security

Despite the increased power of personal computers and departmental workstations, there continues to be a dependency on centralized data centers due to needs for data integration, data consistency, and data quality. With the enormous growth of critical data volumes, many organizations have adopted storage-centric architectures for their ICT infrastructure. Consequently, storage security plays an important role in securing this data, and in many instances, it serves as the last line of defense from both internal and external adversaries.

The design of storage security solutions is guided by core security principles while considering data sensitivity, criticality and value. Section 6 of the standard (Supporting Controls) provides guidance on applying storage-relevant controls in implementing the designed solution. The materials in this section are further divided into:

  • Storage security design principles (Defense in depth, Security domains, Design resilience, and Secure initialization)
  • Data reliability, availability, and resilience (including Backups and replication as well as Disaster Recovery and Business Continuity)
  • Data retention (Long-term and Short to medium-term retention)
  • Data confidentiality and integrity
  • Virtualization (Storage virtualization and Storage for virtualized systems)
  • Design and implementation considerations (Encryption and key management issues, Align storage and policy, Compliance, Secure multi-tenancy, Secure autonomous data movement)

Media sanitization

"Sanitization" is the technical term for assuring that data left on storage at the end of its useful life is rendered inaccessible to a given level of effort. Or to put it another way, sanitization is the process that assures an organization doesn't commit a data breach by repurposing, selling, or discarding storage devices.

Sanitization can take many forms depending on both the sensitivity of the information and the level of effort a likely adversary would invest in attempting to recover the information. Methods used in sanitization range from simple overwrites to destruction of the cryptographic keys for encrypted data (the technique is known as cryptographic erasure) to physical destruction of the storage media. This standard provides guidance to help organizations select the proper sanitization methods for their data.

The specific details on sanitization are provided in a series of tables in Annex A, which were based on NIST Special Publication 800-88 Revision 1.[4] The tables were designed so that vendors can make specific references to them, based on the type of media, instead of using obsolete sources such as DoD 5220.22-M (from 1995).

Selecting appropriate storage security controls

The developers of ISO/IEC 27040 did not intend that all of the guidance had to be implemented (i.e., all or nothing).[who?] Consequently, Annex B was created to help organizations select the appropriate controls based on either data sensitivity (high or low) or security priorities, based on confidentiality, integrity and availability.[who?] To support this selection, all of the storage security controls in ISO/IEC 27040 are listed in 13 different tables along with information that shows how each control is relevant from both data sensitivity and security prioritization perspectives.

It is worth noting that although Annex B is informative, it is very likely that auditors will use it as a basis for checklists when reviewing the security of storage systems and ecosystems.[who?]

Important security concepts

One of the challenges in developing ISO/IEC 27040 was that there were two distinct target audiences: 1) storage professionals and 2) security professionals. To help both communities, Annex C was populated with useful tutorial information[who?] for the following:

References

  1. ^ "ISO/IEC 27040". ISO Standards Catalogue. ISO. Retrieved 2014-06-15.
  2. ^ Eric A. Hibbard; Richard Austin (2007). "SNIA Storage Security Best Current Practices (BCPs)". Storage Network Industry Association.
  3. ^ Eric A. Hibbard (2012). "SNIA Security Tutorial: Storage Security - The ISO/IEC Standard" (PDF). Storage Network Industry Association.
  4. ^ "Special Publication 800-88r1" (PDF). National Institute of Standards and Technology (NIST).

Read other articles:

Peta Bielsko-Biała (diucapkan: /biεlskɔ:biawa/) ialah kota di Polandia selatan dengan penduduk sebanyak 180.307 (1999). Terletak di Provinsi Silesia (sejak 1999), sebelumnya ibu kota Provinsi Bielsko-Biała (1975-1998). Pendidikan Akademia Techniczno-Humanistyczna Bielska Wyższa Szkoła Biznesu i Informatyki im. J. Tyszkiewicza Wyższa Szkoła Administracji Wyższa Szkoła Bankowości i Finansów Wyższa Szkoła Informatyki i Zarządzania Wyższa Szkoła Ekonomiczno-Humanistyczna Politik ...

 

 

Artikel ini perlu dikembangkan dari artikel terkait di Wikipedia bahasa Inggris. (Juli 2023) klik [tampil] untuk melihat petunjuk sebelum menerjemahkan. Lihat versi terjemahan mesin dari artikel bahasa Inggris. Terjemahan mesin Google adalah titik awal yang berguna untuk terjemahan, tapi penerjemah harus merevisi kesalahan yang diperlukan dan meyakinkan bahwa hasil terjemahan tersebut akurat, bukan hanya salin-tempel teks hasil terjemahan mesin ke dalam Wikipedia bahasa Indonesia. Jangan...

 

 

Head of the government of the state of Maharashtra Chief Minister of MaharashtraMahārāṣṭrāce MukhyamaṃtrīEmblem of MaharashtraIncumbentEknath Shindesince 30 June 2022Government of MaharashtraStyleThe HonorableMr. Chief MinisterHis ExcellencyStatusHead of GovernmentAbbreviationCMMember ofVidhan SabhaVidhan ParishadCabinetResidenceVarsha Bungalow, Malabar Hill, MumbaiSeatMantralaya, MumbaiAppointerGovernor of MaharashtraTerm lengthAt the confidence of the assembly5 years and is s...

Prosopocera gahani Klasifikasi ilmiah Kerajaan: Animalia Filum: Arthropoda Kelas: Insecta Ordo: Coleoptera Famili: Cerambycidae Genus: Prosopocera Spesies: Prosopocera gahani Prosopocera gahani adalah spesies kumbang tanduk panjang yang berasal dari famili Cerambycidae. Spesies ini juga merupakan bagian dari genus Prosopocera, ordo Coleoptera, kelas Insecta, filum Arthropoda, dan kingdom Animalia. Larva kumbang ini biasanya mengebor ke dalam kayu dan dapat menyebabkan kerusakan pada batang k...

 

 

Constantin BrâncoveanuBerkuasa1689–1714PendahuluŞerban CantacuzinoPenerusŞtefan CantacuzinoIstriDoamna MariaAnakStanca (1676)( Maria (1678) Ilinca (1682) Constantin (1683)Ştefan (1685) Safta (1686) Radu (1690) Ancuţa (1691)Bălaşa (1693)Smaranda (1696) Matei (1698) Constantin BrâncoveanuTempat ziarahGereja St. George,BukaresPesta16 AgustusPelindungRumania Constantin Brâncoveanu (1654 – 15 Agustus 1714) adalah pangeran Wallachia antara 1689 hingga 1714. Dibawah kekuasaannya, banyak...

 

 

Danish football club Football clubThistedFull nameThisted Fodbold ClubShort nameTFCFounded1989; 35 years ago (1989)GroundSparekassen Thy Arena,ThistedCapacity3,000ChairmanHenrik TinggaardManagerDaniel KristensenLeague2nd Division2022–232nd Division 6th Home colours Away colours Thisted Fodbold Club (Danish pronunciation: [ˈtsʰisteð]) is an association football club based in the town of Thisted, North Jutland, Denmark, that competes in the Danish 2nd Division, th...

Penggalian Neolitik di Skara Brae di Orkney, Skotlandia Skara Brae /ˈskærə ˈbreɪ/ adalah pemukiman Neolitikum yang dibangun dari batu, terletak di Teluk Skaill di pantai barat Daratan, pulau terbesar di kepulauan Orkney, Skotlandia. Terdiri dari sepuluh rumah bergerombol, terbuat dari batu ubin besar, di bendungan tanah yang menopang dinding; rumah-rumah itu termasuk tungku api batu, tempat tidur, dan lemari.[1] Sistem saluran pembuangan primitif, dengan toilet dan saluran air di...

 

 

Questa voce o sezione sull'argomento registi è priva o carente di note e riferimenti bibliografici puntuali. Sebbene vi siano una bibliografia e/o dei collegamenti esterni, manca la contestualizzazione delle fonti con note a piè di pagina o altri riferimenti precisi che indichino puntualmente la provenienza delle informazioni. Puoi migliorare questa voce citando le fonti più precisamente. Segui i suggerimenti del progetto di riferimento. Questa voce o sezione sugli argomenti sce...

 

 

Voce principale: Aurora Pro Patria 1919. Aurora Pro Patria 1919Stagione 2009-2010Sport calcio Squadra Pro Patria Allenatore Giuseppe Manari, poi Vincenzo Cosco, poi Raffaele Di Fusco, poi Gianluca Gaudenzi Presidente Antonio Tesoro Lega Pro Prima Divisione16º posto, retrocede ai playout Coppa ItaliaSecondo turno Coppa Italia Lega ProSecondo turno Maggiori presenzeCampionato: Pacilli (33) Miglior marcatoreCampionato: F. Ripa (12)Totale: F. Ripa (18) StadioCarlo Speroni (4.627) Maggior n...

この記事は検証可能な参考文献や出典が全く示されていないか、不十分です。出典を追加して記事の信頼性向上にご協力ください。(このテンプレートの使い方)出典検索?: コルク – ニュース · 書籍 · スカラー · CiNii · J-STAGE · NDL · dlib.jp · ジャパンサーチ · TWL(2017年4月) コルクを打ち抜いて作った瓶の栓 コルク(木栓、�...

 

 

Державний комітет телебачення і радіомовлення України (Держкомтелерадіо) Приміщення комітетуЗагальна інформаціяКраїна  УкраїнаДата створення 2003Керівне відомство Кабінет Міністрів УкраїниРічний бюджет 1 964 898 500 ₴[1]Голова Олег НаливайкоПідвідомчі ор...

 

 

Державний комітет телебачення і радіомовлення України (Держкомтелерадіо) Приміщення комітетуЗагальна інформаціяКраїна  УкраїнаДата створення 2003Керівне відомство Кабінет Міністрів УкраїниРічний бюджет 1 964 898 500 ₴[1]Голова Олег НаливайкоПідвідомчі ор...

2016年美國總統選舉 ← 2012 2016年11月8日 2020 → 538個選舉人團席位獲勝需270票民意調查投票率55.7%[1][2] ▲ 0.8 %   获提名人 唐納·川普 希拉莉·克林頓 政党 共和黨 民主党 家鄉州 紐約州 紐約州 竞选搭档 迈克·彭斯 蒂姆·凱恩 选举人票 304[3][4][註 1] 227[5] 胜出州/省 30 + 緬-2 20 + DC 民選得票 62,984,828[6] 65,853,514[6]...

 

 

English indie rock band The Pigeon DetectivesBackground informationOriginRothwell, West Yorkshire, EnglandGenresIndie rock[1]Years active2004–present[2]LabelsCooking Vinyl, Dance to the RadioMembersMatt Bowman (vocals)Oliver Main (guitar)Ryan Wilson (guitar)Dave Best (bass guitar)Jimmi Naylor (drums) Paul Spooner (drums, 2004)Websitewww.thepigeondetectives.com The Pigeon Detectives are an English indie rock[1] band from Rothwell in Leeds, West Yorkshire, who formed i...

 

 

国民阵线Barisan NasionalNational Frontباريسن ناسيونلபாரிசான் நேசனல்国民阵线标志简称国阵,BN主席阿末扎希总秘书赞比里署理主席莫哈末哈山总财政希山慕丁副主席魏家祥维纳斯瓦兰佐瑟古律创始人阿都拉萨成立1973年1月1日 (1973-01-01)[1]设立1974年7月1日 (1974-07-01)前身 联盟总部 马来西亚  吉隆坡 50480 秋傑区敦依斯迈路太子世贸中心(英�...

ヨハネス12世 第130代 ローマ教皇 教皇就任 955年12月16日教皇離任 964年5月14日先代 アガペトゥス2世次代 レオ8世個人情報出生 937年スポレート公国(中部イタリア)スポレート死去 964年5月14日 教皇領、ローマ原国籍 スポレート公国親 父アルベリーコ2世(スポレート公)、母アルダその他のヨハネステンプレートを表示 ヨハネス12世(Ioannes XII、937年 - 964年5月14日)は、ロ...

 

 

巴西昵称Canarinho(Little Canary)A Seleção(The Selection)Verde-Amarela(Green and Yellow)协会巴西足球协会联合会南美足联主教练Marcos Sorato Pipoca助理教练Vander Iacovino队长Vinícius神射手Falcão (299)主场VariousFIFA代码BRAFIFA排名2 [1]最高FIFA排名1 (22 January 1996) 主場球衣 客場 球衣 最大比分勝利 Brazil 76–0 East Timor (Macau, Macau; 13 October 2006) (World Record international score) 最大比分失利 Brazil 1–6 Netherlands...

 

 

First primate and first mammal in space On June 14, 1949, V-2 launch No. 47 at Holloman Air Force Base in New Mexico carried Albert II to become the first primate and first mammal in space Albert II was a male rhesus macaque monkey who was the first primate and first mammal in space. He flew from Holloman Air Force Base in New Mexico, United States, to an altitude of 83 miles (134 km) aboard a U.S. V-2 sounding rocket on June 14, 1949. Albert died upon reentry after a parachute failure cause...

Ipswich Town 2018–19 football seasonIpswich Town2018–19 seasonOwnerMarcus EvansManagerPaul Hurst(until 25 October 2018)[1]Bryan Klug (caretaker)(25–27 October 2018)[2]Paul Lambert(from 27 October 2018)[3]StadiumPortman RoadChampionship24th (relegated)FA CupThird roundEFL CupFirst roundTop goalscorerLeague: Gwion Edwards / Freddie Sears (6)All: Gwion Edwards / Freddie Sears (6)Highest home attendance25,690(vs Norwich City, 2 Sep 2018, EFL Championship)Lowest home...

 

 

Marvel Films beralih ke halaman ini. Untuk kegunaan lain, lihat Daftar film yang diadaptasi dari Marvel Comics. Marvel Studios, LLCJenisAnak perusahaanIndustriFilmGenrePahlawan superPendahuluMarvel ProductionsDidirikan1993; 31 tahun lalu (1993)PendiriAvi AradToyBizMarvel Entertainment GroupKantorpusat500 S. Buena Vista Street,Burbank, California[1], Amerika SerikatTokohkunciKevin Feige(Presiden)Louis D'Esposito(Wakil presiden)[2]ProdukFilmIndukWalt Disney Studios(The Walt...