Home > Security Tips > Compliance Counselor > Watch those permissions
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE COUNSELOR

Watch those permissions


Rick Cook
12.20.2000
Rating: -2.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   




Although we usually think of "security" in storage as meaning not losing data, it's important to realize that storage systems face risks from malicious tampering or data theft, as well. This is especially true of network-attached storage (NAS), where server and storage are combined and hooked onto the network.

The major concern for storage administrators is to make sure that the appropriate permission levels are set to allow only authorized users access to the data on the NAS server. Although many modern NAS servers can be brought up in a matter of minutes, it can take a lot longer to set the appropriate permissions for users to access the data. There is a related problem in a heterogeneous environment where the same server may be supplying data to both Unix and Windows NT systems. Unix and NT use significantly different methods of controlling access to files.

Unix NFS security is based on a distributed model, where, broadly speaking, each machine on the network is responsible for maintaining its own security. NT uses a more centralized approach with a single Primary Domain Controller (PDC) managing permissions for the entire domain via access control lists (ACLs). There needs to be some method of translating between the different kinds of permissions if Unix users are to be allowed to access NT files -- and vice-versa -- safely. In NAS servers that support heterogeneous access, the translation is almost always done by the server's operating system.

Procom Technology Inc. has a more detailed explanation of NT and Unix permissions and how they differ, as well as a discussion of how the company's NetForce NAS server handles the problem.

About the author
Rick Cook has been writing about mass storage since the days when the term meant an 80K floppy disk. The computers he learned on used ferrite cores and magnetic drums. For the last twenty years he has been a freelance writer specializing in storage and other computer issues.


Related book

The Holy Grail of Data Storage Management
By Jon William Toigo
Depending on the analyst one follows, corporate IT departments will spend between 75 and 90 cents of every dollar over the next five years on data storage products. The reason is simple: Companies are generating data at a phenomenal rate and increasing their requirements for data storage by 100 percent or more per year. In The Holy Grail of Data Storage Management, Jon William Toigo documents current trends in storage technology and shows IT executives exactly how to plan a comprehensive strategy for maximizing the availability, performance and cost-effectiveness of enterprise storage.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Compliance Counselor
Security and audit relationships: Uneasy antagonists or partners in arms?
Security beyond compliance: A proactive and customized security framework
Cloud compliance: How to manage SaaS risk
Richard Mackey: Building a framework-based compliance program
Learning the language of global compliance
WEP to WPA: Wireless encryption in the wake of PCI DSS 1.2
HIPAA privacy regulations get some teeth: Be prepared
PCI version 1.2 clarifications: How to get an early start on compliance audits
Version 1.2 of Payment Card Industry (PCI) Data Security Standard answers questions, raises others
Security certifications: Are they worth the trouble?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts