Thursday, November 6, 2008

Securing Data at Rest, Pt. II

Talked to Jesse last night. Asked him about our situation and options. He had two suggestions.

First, if we go the appliance route, we should look at Decru (the top of the line, which Net App OEMs), Brocade, or Cisco. He says the Decru would be around 40K each, with three necessary to form a quorum and prevent any key loss. He estimates the Cisco at around 20K, but suggested that we price it ourselves. Due to the great cost for a company as small as ours, he advises us to bundle the cost of these appliance with the addition of a client contract.

Second, his suggestion is that perhaps the insurance industry is not as interested in the encryption of intermediate storage, but more interested in the encryption of archival data. In that case, we could get a tape drive that encrypts on write. This would be the most economical option, in his opinion.

I briefly considered homegrown in-band encryption on an additional server on our network, but he pointed out that that's basically just creating your own appliance. Good point. I'm guessing the main constraint governing any decision here will be price.

No comments: