Find White Papers
Home
About Us
List Your Papers
    
> CA Mainframe > Best Practices for Tape Encryption

Best Practices for Tape Encryption

White Paper Published By: CA Mainframe

Increased regulatory scrutiny on the protection levels afforded sensitive information by those that transact and process it is causing enterprises to improve mainframe security strategies. This entails proactively investigating exposures and implementing appropriate policies, processes and technologies, including those for data z/OS tape encryption. Read this Technology Brief created by CA to learn how to identify exposure points and through the use of Tape Encryption.



Tags : 
tape library, tape backup, tape encryption, backup, encryption, best practices, ca mainframe, mainframe

CA Mainframe
Published:  Sep 12, 2008
Type:  White Paper
Length:  12 pages


WHITE PAPER: DATA ENCRYPTION BEST PRACTICES FOR MAINFRAME TAPE
Employing Best Practices
for Mainframe Tape
Encryption
JUNE 2008
Stefan KochishanCA MAINFRAME PRODUCT MARKETING
John HillCA MAINFRAME PRODUCT MANAGEMENTTable of Contents
Executive Summary 1 SECTION 4: CONCLUSIONS 6
SECTION 1: CHALLENGE 2 SECTION 5: REFERENCES 6Securing Personal and Business-critical Data There's No Such Thing as Low Risk SECTION 6: ABOUT THE AUTHORS 7Encryption is KeyThe Real Cost of Exposure
SECTION 2: OPPORTUNITY 3Minimizing Risk and LossFinding the Right Balance
SECTION 3: BENEFITS 4Implementing Best Practices for Better ResultsThe Data Selection Process
Copyright © 2008 CA. All rights reserved. All trademarks, trade names, service marks and logos referenced herein belong to their respective companies. This document is for your informational purposes only. To the extent permittedby applicable law, CA provides this document "As Is" without warranty of any kind, including, without limitation, any implied warranties of merchantability or fitness for a particular purpose, or noninfringement. In no event will CA beliable for any loss or damage, direct or indirect, from the use of this document, including, without limitation, lost profits, business interruption, goodwill or lost data, even if CA is expressly advised of such damages. Executive Summary
Challenge
Increased regulatory scrutiny on the protection levels afforded sensitive information bythose that transact and process it is causing enterprises to improve mainframe securitystrategies. This entails proactively investigating exposures and implementing appropriatepolicies, processes and technologies, including those for data z/OS tape encryption.
Opportunity
Organizations need to identify exposure points and the information in need of encryption,taking steps to avoid encrypting too much or too little - or both. To that aim, they need toimplement tape encryption policies that protect all sensitive data without burning moneyand man hours safeguarding information that doesn't require that higher level of security.
Benefits
Because all data is not created equal, it's best to consider a tape encryption strategy that'saligned with business practices, security objectives and compliance drivers. But, the finalreality check would be to judge if a data set satisfies the minimal non-disclosure criteria ofexisting or emerging regulatory requirements. Doing this comparison will help enterprisesaddress both the spirit and letter of applicable mandates as they apply to the security andprotection of personal and business-critical data.
WHITE PAPER: DATA ENCRYPTION BEST PRACTICES FOR MAINFRAME TAPE 1SECTION 1: CHALLENGE
Securing Personal and Business-critical Data There's No Such Thing as Low RiskData loss incidents expose enterprises and their partners, clients, constituents and employeesto a multitude of risks. After all, unauthorized and rogue access to sensitive personal andbusiness-critical information often results in identity theft, and ultimately, adversely affects:. Consumer credit ratings . Press coverage . Organizational reputation and perception. The bottom line via citations and fines for noncompliance
Unless steps are taken to secure data by all businesses and governmental agencies, thesituation simply promises to get worse. In fact, millions of individuals are impacted by data lossevery year. And as criminals increase their sophistication and we become more dependent ontechnology, the collateral damage will continue to grow exponentially. That means that there isno such thing as a low-risk organization or low-risk personal information. It also means aninstitution's trustworthiness is the least of its concerns.
Encryption is Key Data breach exposures aren't hype - they're very real and can have significant impact on anorganization. And because all data is now business critical, many US and EU governing bodieshave written laws that:. Protect consumer data identities. Require businesses to be proactive in disclosure and remediation. Levy hefty fines for incidents of exposure
To date, nearly all of the 50 US states have enacted legislation requiring companies andgovernment agencies to report loss or theft of personal information when the exposed data isnot encrypted.
Thus, encryption for mainframe tapes has rap... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search