- Security TWENTY
- Women in Security
Reappraising tape storage: why keeping all your data “just in case” is no longer an option, by Paul Le Messurier, Head of Programmes and Operations for Western Europe, Kroll Ontrack.
The death of tape as a corporate storage medium has been greatly exaggerated. The vast majority of organisations still use tape to back up data either onsite or offsite. Indeed, as the volume of data continues to rise exponentially, off-site tape capacity is only expected to increase significantly. Historically, the low cost of tape storage has only encouraged organisations to keep and store all data “just in case”. This has served to bloat IT budgets unnecessarily and increase e-discovery risks and costs when an investigation, litigation or merger/ acquisition occur.
The problem is that many organisations, even household names, have lost track of the data that they have stored on tape. There are many fundamental questions that cannot be answered quickly or efficiently. What content are we currently storing? Is it located on-site, off-site or at a storage vendor – and if so, on which tape? What data is truly necessary for business continuity or legal purposes versus duplicate or irrelevant data that should be disposed of?
Some information never expires and may already be in storage, such as proprietary drawings, prototypes or formulas. If this, and other types of data, must be retained for longer and longer time periods, what is the plan to ensure it remains accessible as current technology becomes obsolete and the operational costs to maintain legacy systems purely for restoration purposes is no longer practical?
If an organisation doesn’t address these questions via a well-defined process, the default answer for both stored data and legacy systems automatically becomes “keep everything.” On a practical level, information about managing types of content is rarely tracked and communicated via an existing Service Level Agreement (SLA) and the unnecessary expense and risk multiplies.
Lack of clarity about what is stored on tape is only one problem. Another important issue is that historical data can be difficult to access from tape storage. Organisations routinely backup and store information, thinking their processes are strong and the data is sound. However, a variety of issues including user error and hardware/software faults can hinder data retrieval, some of which are never discovered until the organisation is in reactive crisis mode and scrambling for alternatives. Regardless of the technical issue, an organisation has a duty to preserve relevant data upon reasonable notice of litigation. Common problems that can occur when accessing data on tape include:
Backup Software Failure:
Backup software is set up correctly and the process is kicked off. However, the actual backup data itself is never verified so it does not register and the data cannot be located when it is required.
Storage Media Failure:
Tape drive failure; corrupt or inaccessible tapes; where the information written to tape can’t be read because of logical errors in the data. There is a significant difference between data from the last backup versus data from the point of failure.
Errors such as accidentally re-initialising a tape or forgetting to enable the append option before starting a backup are common.
Volume of Data and “Findability”:
Sheer volume of data and the ability to find specific content within the corporate memory is a common problem. How do you know if data is lost or missing? For example, when companies merge, the operational, accounting, and client data of both companies needs to continue to be available. The various backup landscapes have to be harmonised (eg. proprietary backup systems in Windows environments.)
Ageing Systems and Obsolescence:
There is a need to maintain legacy data; converting old static systems to another format or newer technology. Auditors may also request submission of old data records – such as, in the case of one bank, the submission of 17,000 sets of entries from the 1980s. The tapes were available, but the software and drives were no longer serviceable.
Disaster: Fire, water damage, mud, extraordinary cold, heat or other natural catastrophes are often the reasons for tapes becoming contaminated, damaged and no longer legible using the standard means.
Forensically Unsound Methods:
The data may be “readable” by a human – but moving data incorrectly can modify the file or system metadata relied upon for compliance, investigative, and e-discovery purposes. If this results in making the data difficult – if not impossible – to recover it will not excuse a corporation from its duty to provide the information required. Some organisations are simply gambling that their legacy data will not be an issue and will be accessible and usable if and when they need it. Within the larger context of information life cycle management, organisations are looking to data management experts such as Kroll Ontrack to help them manage stored data more efficiently and reduce the load on IT personnel and infrastructure.
Historically, it has been time consuming, technically difficult, and cost-prohibitive to incorporate legacy data into an organisation’s overall information life cycle management (ILM) plan. After relying on IT to restore the data, legal would work with IT to analyse the relevant data required to support an investigation or lawsuit. Due to budget and infrastructure limitations, restoring thousands or tens of thousands of tapes was not feasible.
The problem has been addressed by using technology to streamline the entire process. Rather than rely on a false sense of security, many corporations seek expert consultative assistance with proven experience using forensically sound methods and deep expertise in legal, compliance, and IT issues. Common procedures that are included in the process are:
Data Identification, Mapping and Collection: Locate, preserve and collect business critical and legally relevant data
Migration: Safely migrate large amounts of data to alternative media or formats
Media Consolidation: Combine incremental or differential backups into one backup
Media Conversion: Seamlessly convert data from one format to another
Tape Cataloguing: Catalogue to save time, money and resources
Tape Duplication: Reproduce data with ease
Tape Ingestion: Prepare to ingest identified files or tapes into a legal hold or archiving system.
The perfect storm of a highly regulatory environment, rapidly growing amounts of big data and the need for greater responsiveness and transparency means that organisations need to address the issue of poorly managed tape storage sooner rather than later.
It is not in anyone’s interests to leave the huge task of sorting and cataloguing data stored on ageing tapes to the 11th hour, or when regulators come knocking at the door.
About the writer
He joined Kroll Ontrack last year from his most recent role at Samsung SDS Europe, where he was Head of Business Development for the EMEA region. Other roles within Samsung included Head of IT Services and Support and Senior IT Manager. Visit http://www.krollontrack.co.uk