Information technology - Security techniques - Storage security (ISO/IEC 27040:2015)

ISO/IEC 27040:2015 provides detailed technical guidance on how organizations can define an appropriate level of risk mitigation by employing a well-proven and consistent approach to the planning, design, documentation, and implementation of data storage security. Storage security applies to the protection (security) of information where it is stored and to the security of the information being transferred across the communication links associated with storage. Storage security includes the security of devices and media, the security of management activities related to the devices and media, the security of applications and services, and security relevant to end-users during the lifetime of devices and media and after end of use.
Storage security is relevant to anyone involved in owning, operating, or using data storage devices, media, and networks. This includes senior managers, acquirers of storage product and service, and other non-technical managers or users, in addition to managers and administrators who have specific responsibilities for information security or storage security, storage operation, or who are responsible for an organization's overall security program and security policy development. It is also relevant to anyone involved in the planning, design, and implementation of the architectural aspects of storage network security.
ISO/IEC 27040:2015 provides an overview of storage security concepts and related definitions. It includes guidance on the threat, design, and control aspects associated with typical storage scenarios and storage technology areas. In addition, it provides references to other International Standards and technical reports that address existing practices and techniques that can be applied to storage security.

Informationstechnik - IT-Sicherheitsverfahren - Speichersicherheit (ISO/IEC 27040:2015)

Technologie de l'information - Techniques de sécurité - Sécurité de stockage (ISO/IEC 27040:2015)

L'ISO/IEC 27040:2015 donne des préconisations techniques détaillées concernant la manière dont les organismes peuvent définir un niveau approprié d'atténuation du risque grâce à l'emploi d'une approche reconnue et cohérente de la planification, la conception, la documentation et la mise en ?uvre de la sécurité de stockage des données. La sécurité du stockage s'applique à la protection (la sécurité) des informations là où elles sont stockées et à la sécurité des informations transférées au moyen des liaisons de communication associées au stockage. La sécurité du stockage comprend la sécurité des dispositifs et des supports, la sécurité des activités de management associées aux dispositifs et aux supports, la sécurité des applications et des services et la sécurité relative aux utilisateurs finaux pendant la durée de vie de leurs dispositifs et supports et après la fin de leur utilisation.
La sécurité du stockage concerne toute personne impliquée dans la possession, l'exploitation ou l'utilisation de dispositifs, supports et réseaux de stockage de données. Il s'agit des cadres supérieurs, des acheteurs de produits et services de stockage et d'autres gestionnaires ou utilisateurs non techniciens, outre les gestionnaires et administrateurs ayant des responsabilités spécifiques en matière de sécurité de l'information ou de sécurité du stockage, d'exploitation du stockage, ou responsables du programme général de sécurité et du développement des politiques de sécurité de l'organisme. Elle concerne également toute personne impliquée dans la planification, la conception et la mise en ?uvre des aspects architecturaux de la sécurité des réseaux de stockage.
L'ISO/IEC 27040:2015 propose une description générale des concepts de sécurité du stockage et des définitions associées. Elle comprend des préconisations concernant les aspects relatifs aux menaces, à la conception et au contrôle ainsi que des scénarios de stockage et des technologies de stockage typiques. Elle donne de plus des références à d'autres Normes internationales et rapports techniques qui traitent des pratiques et techniques existantes pouvant être appliquées à la sécurité du stockage.

Informacijska tehnologija - Varnostne tehnike - Varnostno shranjevanje (ISO/IEC 27040:2015)

Ta mednarodni standard podaja podrobne tehnične smernice, kako lahko organizacije določijo
ustrezno raven za zmanjšanje tveganja z uporabo dobro preizkušenih in doslednih pristopov k
načrtovanju, oblikovanju, dokumentiranju in izvajanju varnostnega shranjevanja podatkov. Varnostno shranjevanje velja za zaščito (varnost) informacij na mestu shranjevanja in za varnost informacij, ki se prenašajo prek komunikacijskih povezav, povezanih s shranjevanjem. Varnostno shranjevanje vključuje varnost naprav in medijev, varnost aktivnosti upravljanja, povezanih z napravami in mediji, varnost aplikacij in storitev ter varnost v zvezi s končnimi uporabniki v času življenjske dobe naprav in medijev ter po koncu uporabe.
Varnost shranjevanja je pomembna vsem, ki si lastijo, upravljajo ali uporabljajo naprave, medije in
omrežja za shranjevanje podatkov. To vključuje višje vodstvene delavce, odjemalce izdelkov in storitev za shranjevanje ter
druge netehnične upravitelje ali uporabnike poleg upraviteljev in skrbnikov s posebnimi odgovornostmi za upravljanje informacijske varnosti ali varnosti shranjevanja, delovanje shranjevanja ali oseb, ki so odgovorne za celoten varnostni program in razvoj varnostnega pravilnika v organizaciji. Prav tako je pomembna vsem, ki so vključeni v načrtovanje, oblikovanje in izvajanje arhitekturnih vidikov varnosti omrežja za shranjevanje.
Ta mednarodni standard podaja pregled nad koncepti varnosti shranjevanja in povezanih definicij. Vključuje smernice za vidike groženj, zasnove in nadzora, povezane z običajnimi scenariji shranjevanja in področji tehnologije shranjevanja. Poleg tega podaja sklice na druge mednarodne standarde in tehnična poročila, ki obravnavajo obstoječe prakse in tehnike, ki jih je mogoče uporabiti pri varnosti shranjevanja.

General Information

Status
Published
Publication Date
23-Aug-2016
Withdrawal Date
27-Feb-2017
Current Stage
6060 - Definitive text made available (DAV) - Publishing
Start Date
24-Aug-2016
Due Date
02-Sep-2017
Completion Date
24-Aug-2016

Buy Standard

Standard
EN ISO/IEC 27040:2017 - BARVE
English language
120 pages
sale 10% off
Preview
sale 10% off
Preview
e-Library read for
1 day

Standards Content (Sample)


SLOVENSKI STANDARD
01-januar-2017
Informacijska tehnologija - Varnostne tehnike - Varnostno shranjevanje (ISO/IEC
27040:2015)
Information technology - Security techniques - Storage security (ISO/IEC 27040:2015)
Informationstechnik - IT-Sicherheitsverfahren - Speichersicherheit (ISO/IEC 27040:2015)
Technologie de l'information - Techniques de sécurité - Sécurité de stockage (ISO/IEC
27040:2015)
Ta slovenski standard je istoveten z: EN ISO/IEC 27040:2016
ICS:
35.030 Informacijska varnost IT Security
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

EN ISO/IEC 27040
EUROPEAN STANDARD
NORME EUROPÉENNE
August 2016
EUROPÄISCHE NORM
ICS 35.040
English Version
Information technology - Security techniques - Storage
security (ISO/IEC 27040:2015)
Technologie de l'information - Techniques de sécurité - Informationstechnik - IT-Sicherheitsverfahren -
Sécurité de stockage (ISO/IEC 27040:2015) Speichersicherheit (ISO/IEC 27040:2015)
This European Standard was approved by CEN on 19 June 2016.

CEN and CENELEC members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions
for giving this European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical
references concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to
any CEN and CENELEC member.
This European Standard exists in three official versions (English, French, German). A version in any other language made by
translation under the responsibility of a CEN and CENELEC member into its own language and notified to the CEN-CENELEC
Management Centre has the same status as the official versions.

CEN and CENELEC members are the national standards bodies of Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic,
Denmark, Estonia, Finland, Former Yugoslav Republic of Macedonia, France, Germany, Greece, Hungary, Iceland, Ireland, Italy,
Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden,
Switzerland, Turkey and United Kingdom.

EUROPEAN COMMITTEE FOR STANDARDIZATION
COMITÉ EUROPÉEN DE NORMALISATIO N

EUROPÄISCHES KOMITEE FÜR NORMUN G

CEN-CENELEC Management Centre: Avenue Marnix 17, B-1000 Brussels
© 2016 CEN and CENELEC All rights of exploitation in any form and by any means Ref. No. EN ISO/IEC 27040:2016 E
reserved worldwide for CEN and CENELEC national
Members.
Contents Page
European foreword . 3

European foreword
The text of ISO/IEC 27040:2015 has been prepared by Technical Committee ISO/IEC JTC 1 “Information
technology” of the International Organization for Standardization (ISO) and the International
Electrotechnical Commission (IEC) and has been taken over as EN ISO/IEC 27040:2016.
This European Standard shall be given the status of a national standard, either by publication of an
identical text or by endorsement, at the latest by February 2017, and conflicting national standards
shall be withdrawn at the latest by February 2017.
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CEN [and/or CENELEC] shall not be held responsible for identifying any or all such patent
rights.
According to the CEN-CENELEC Internal Regulations, the national standards organizations of the
following countries are bound to implement this European Standard: Austria, Belgium, Bulgaria,
Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, Former Yugoslav Republic of Macedonia,
France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta,
Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Switzerland,
Turkey and the United Kingdom.
Endorsement notice
The text of ISO/IEC 27040:2015 has been approved by CEN as EN ISO/IEC 27040:2016 without any
modification.
INTERNATIONAL ISO/IEC
STANDARD 27040
First edition
2015-01-15
Information technology — Security
techniques — Storage security
Technologie de l’information — Techniques de sécurité — Sécurité de
stockage
Reference number
ISO/IEC 27040:2015(E)
©
ISO/IEC 2015
ISO/IEC 27040:2015(E)
© ISO/IEC 2015
All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized otherwise in any form
or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior
written permission. Permission can be requested from either ISO at the address below or ISO’s member body in the country of
the requester.
ISO copyright office
Case postale 56 • CH-1211 Geneva 20
Tel. + 41 22 749 01 11
Fax + 41 22 749 09 47
E-mail copyright@iso.org
Web www.iso.org
Published in Switzerland
ii © ISO/IEC 2015 – All rights reserved

ISO/IEC 27040:2015(E)
Contents Page
Foreword .v
Introduction .vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Symbols and abbreviated terms . 7
5 Overview and concepts .11
5.1 General .11
5.2 Storage concepts .12
5.3 Introduction to storage security .12
5.4 Storage security risks .14
5.4.1 Background.14
5.4.2 Data breaches .15
5.4.3 Data corruption or destruction .16
5.4.4 Temporary or permanent loss of access/availability .16
5.4.5 Failure to meet statutory, regulatory, or legal requirements .17
6 Supporting controls .17
6.1 General .17
6.2 Direct Attached Storage (DAS) .17
6.3 Storage networking .18
6.3.1 Background.18
6.3.2 Storage Area Networks (SAN) .18
6.3.3 Network Attached Storage (NAS) .23
6.4 Storage management .24
6.4.1 Background.24
6.4.2 Authentication and authorization .26
6.4.3 Secure the management interfaces .27
6.4.4 Security auditing, accounting, and monitoring .28
6.4.5 System hardening .30
6.5 Block-based storage .31
6.5.1 Fibre Channel (FC) storage .31
6.5.2 IP storage .31
6.6 File-based storage .32
6.6.1 NFS-based NAS .32
6.6.2 SMB/CIFS-based NAS . .33
6.6.3 Parallel NFS-based NAS .33
6.7 Object-based storage .34
6.7.1 Cloud computing storage .34
6.7.2 Object-based Storage Device (OSD) .35
6.7.3 Content Addressable Storage (CAS) .36
6.8 Storage security services .37
6.8.1 Data sanitization .37
6.8.2 Data confidentiality .40
6.8.3 Data reductions .42
© ISO/IEC 2015 – All rights reserved iii

ISO/IEC 27040:2015(E)
7 Guidelines for the design and implementation of storage security .43
7.1 General .43
7.2 Storage security design principles .43
7.2.1 Defence in depth .43
7.2.2 Security domains .
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.