SNIA 100 Year Archive Survey 2017 Thomas Rivera, CISSP

Similar documents
Format Technologies for the Long Term Retention of Big Data

Combining SNIA Cloud, Tape and Container Format Technologies for the Long Term Retention of Big Data

Format Technologies for the Long Term Retention of Big Data. Roger Cummings, Antesignanus Co-Author: Simona Rabinovici-Cohen, IBM Research Haifa

Format Technologies for the Long Term Retention of Big Data

The Storage Networking Industry Association (SNIA) Data Preservation and Metadata Projects. Bob Rogers, Application Matrix

LTR TWG & the Cloud PRESENTATION TITLE GOES HERE

Cloud Archive and Long Term Preservation Challenges and Best Practices

The Need for a Terminology Bridge. May 2009

Tom Sas HP. Author: SNIA - Data Protection & Capacity Optimization (DPCO) Committee

Solution Brief. Bridging the Infrastructure Gap for Unstructured Data with Object Storage. 89 Fifth Avenue, 7th Floor. New York, NY 10003

CYBERSECURITY HOW IT IS TRANSFORMING THE IT ASSURANCE FIELD

ADVANCED DEDUPLICATION CONCEPTS. Thomas Rivera, BlueArc Gene Nagle, Exar

ADVANCED DATA REDUCTION CONCEPTS

Cybersecurity The Evolving Landscape

Records Information Management

Restoration Technologies

Digital Preservation at NARA

General Data Protection Regulation: Knowing your data. Title. Prepared by: Paul Barks, Managing Consultant

Investing in a Better Storage Environment:

More than a Lifetime of

COMPREHENSIVE RETENTION COMPLIANCE: HOW KEEPITSAFE ONLINE BACKUP CAN HELP YOUR BUSINESS

SOC for cybersecurity

HCISPP HealthCare Information Security and Privacy Practitioner

Engaging Executives and Boards in Cybersecurity Session 303, Feb 20, 2017 Sanjeev Sah, CISO, Texas Children s Hospital Jimmy Joseph, Senior Manager,

Active Archive and the State of the Industry

in Transition to the Cloud David A. Chapa, CTE EVault, a Seagate Company

Cybersecurity Fundamentals

TDWI Data Governance Fundamentals: Managing Data as an Asset

Protecting Future Access Now Models for Preserving Locally Created Content

Administration and Data Retention. Best Practices for Systems Management

PONEMON INSTITUTE RESEARCH REPORT 2018 STUDY ON GLOBAL MEGATRENDS IN CYBERSECURITY

The digital preservation technological context

Protecting Data in the Big Data World

Vice President and Chief Information Security Officer FINRA Technology, Cyber & Information Security

Importance of the Data Management process in setting up the GDPR within a company CREOBIS

ISACA GEEK WEEK SECURITY MANAGEMENT TO ENTERPRISE RISK MANAGEMENT USING THE ISO FRAMEWORK AUGUST 19, 2015

STRATEGIC PLAN

THE STATE OF CLOUD & DATA PROTECTION 2018

Turning Risk into Advantage

Managing Official Electronic Records Guidelines

Agenda. Bibliography

DRI: Preservation Planning Case Study Getting Started in Digital Preservation Digital Preservation Coalition November 2013 Dublin, Ireland

Higher Education Privacy Update

Pennsylvania s HIE Journey

What It Takes to be a CISO in 2017

Self-contained Information Retention Format For Future Semantic Interoperability

Leading the Digital Transformation from the Centre of Government

Isaca EXAM - CISM. Certified Information Security Manager. Buy Full Product.

IMPLEMENTING SECURITY, PRIVACY, AND FAIR DATA USE PRINCIPLES

Exam4Tests. Latest exam questions & answers help you to pass IT exam test easily

Secure Messaging is far more than traditional encryption.

Overview of Archiving. Cloud & IT Services for your Company. EagleMercury Archiving

Woodson Research Center Digital Preservation Policy

Leveraging High Performance Computing Infrastructure for Trusted Digital Preservation

DRS Policy Guide. Management of DRS operations is the responsibility of staff in Library Technology Services (LTS).

U.S. Japan Internet Economy Industry Forum Joint Statement October 2013 Keidanren The American Chamber of Commerce in Japan

Guide. A small business guide to data storage and backup

The Challenge of Cloud Security

ISAO SO Product Outline

State Government Digital Preservation Profiles

HIPAA Compliance and OBS Online Backup

How to avoid storms in the cloud. The Australian experience and global trends

Digital Preservation Policy. Principles of digital preservation at the Data Archive for the Social Sciences

Google Message Discovery

Governance for the Public Sector Cloud

Storage & Data Management Practices for the Long Term. Raymond A. Clarke Enterprise Storage Consultant Data Management Group Sun Microsystems, Inc.

But first, about me you 5/16/2017. Sensitive Data Breach: Not If, But When June 5, Session Objectives

Key Findings from the Global State of Information Security Survey 2017 Indonesian Insights

Cipherpost Pro is far more than traditional encryption.

Emerging Technologies The risks they pose to your organisations

Information Security in Corporation

THALES DATA THREAT REPORT

Abstract: Data Protection Cloud Strategies

WHITE PAPER. Header Title. Side Bar Copy. Header Title 5 Reasons to Consider Disaster Recovery as a Service for IBM i WHITEPAPER

IT Security in a Meaningful Use Era C&SO HIMSS Meeting

Subject: University Information Technology Resource Security Policy: OUTDATED

Can a Consortium Build a Viable Preservation Repository?

Cloud Computing Standard 1.1 INTRODUCTION 2.1 PURPOSE. Effective Date: July 28, 2015

Managing Born- Digital Documents.

Thomas Rivera / Hitachi Data Systems. Author: SNIA - Data Protection & Capacity Optimization (DPCO) Committee

TEL2813/IS2820 Security Management

a publication of the health care compliance association MARCH 2018

Technical Challenges in Digital Preservation

The Data Management Plan: Putting policy into practice Suzanne Clarke Director, Information Resources

GIIM. Global Institute for IT Management. A unique (outside-of-the-box) approach for educating executives

The International Journal of Digital Curation Issue 1, Volume

A Promise Kept: Understanding the Monetary and Technical Benefits of STaaS Implementation. Mark Kaufman, Iron Mountain

UAE National Space Policy Agenda Item 11; LSC April By: Space Policy and Regulations Directory

Hitachi Content Archive Platform

CoSA & Preservica Practical Digital Preservation 2015/16. Practical OAIS Digital Preservation Online Workshop Module 2

Healthcare HIPAA and Cybersecurity Update

Modern Database Architectures Demand Modern Data Security Measures

GUIDELINES FOR CREATION AND PRESERVATION OF DIGITAL FILES

State Government Digital Preservation Profiles

A Vendor Agnostic Overview. Walt Hubis Hubis Technical Associates

Trusted Digital Repositories. A systems approach to determining trustworthiness using DRAMBORA

INTELLIGENCE DRIVEN GRC FOR SECURITY

A Global Look at IT Audit Best Practices

Symantec Document Retention and Discovery

Information Security Risk Strategies. By

Transcription:

SNIA 100 Year Archive Survey 2017 Thomas Rivera, CISSP Data Security & Privacy Consultant Co-chair, Data Protection & Capacity Optimization (DPCO)Committee SNIA Secretary, Board of Directors SNIA Secretary, Cybersecurity & Privacy Standards Committee IEEE 2017 Storage Developer Conference SNIA All Rights Reserved. 1

Participating SNIA Groups Long-term Retention Technical Working Group (LTR TWG) SNIA s LTR TWG developed a SNIA standard for a logical container format called the Self-contained Information Retention Format (SIRF) This new standard enables long-term hard disk, cloud, and tape-based containers a way to effectively & efficiently preserve and secure digital information for many decades, even with the ever-changing technology landscape For more info on LTR TWG: http://www.snia.org/ltr Data Protection & Capacity Optimization (DPCO) Committee The mission of the DPCO is to foster the growth and success of the market for data protection and capacity optimization technologies For more info on the DPCO Committee: https://www.snia.org/dpco 2017 Storage Developer Conference SNIA All Rights Reserved. 2

The Need for Digital Preservation of Big Data Regulatory compliance and legal issues Sarbanes-Oxley, HIPAA, FRCP, intellectual property litigation Emerging web services and applications Email, photo sharing, web site archives, social networks, blogs Many other fixed-content repositories Scientific data, intelligence, libraries, movies, music Domains that have Big Data require preservation Scientific & Cultural Satellite data is kept for ever X-rays often stored for periods of 75 yrs Healthcare Media & Entertainment Film Masters, Out-takes; Related artifacts (e.g., games) ~100 Yrs Digital art is kept for ever Records of minors are needed until age 20 to 43 yrs 2017 Storage Developer Conference SNIA All Rights Reserved. 3

Goals of Digital Preservation Digital assets stored now should remain Accessible Undamaged Usable For as long as desired beyond the lifetime of Any particular storage system Any particular storage technology And at an affordable cost 2017 Storage Developer Conference SNIA All Rights Reserved. 4

Threats to Long-term Assets Large-scale disaster Human error Media faults Component faults Economic faults Attack Organizational faults Long-term content suffers from more threats than short-term content Media/hardware obsolescence Software/format obsolescence Lost context/metadata 2017 Storage Developer Conference SNIA All Rights Reserved. 5

2007 SNIA Archive Survey Ten years ago, the SNIA 100 Year Archive Task Force developed a survey with the following goal and hypothesis: Goal: Determine the requirements for long-term digital information retention in the data center. These requirements are needed to frame the definition of best practices and solutions to the retention and preservation problems unique to large, scalable data centers* Research Hypothesis: Practitioner's experiences with terabyte-size archival systems are adequate to define the business and operating requirements for petabyte-size information repositories in the data center* * Quoted from the SNIA 100 Year Archive Requirements Survey Report (2007) 2017 Storage Developer Conference SNIA All Rights Reserved. 6

2007 SNIA Archive Survey (Cont.) >100 Years >50-100 Years >21-50 Years >11-20 Years >7-10 Years 18.3% 38.8% 13.1% 15.7% 12.3% What does Long-Term Mean? Retention of 20 years or more is required by 70% of responses >3-6 Years 1.9% 0.0% 5.0% 10.0% 15.0% 20.0% 25.0% 30.0% 35.0% 40.0% Source: SNIA-100 Year Archive Requirements Survey, January 2007 2017 Storage Developer Conference SNIA All Rights Reserved. 7

2007 SNIA Archive Survey (Cont.) Top External Factors Driving Long-Term Retention Requirements: Legal Risk Compliance Regulations Business Risk Security Risk Preservation of business history Protection of customer privacy Protection of business or intellectual assets Retaining history for competitiveness or protection Protection from compliance or legal fines Meeting regulatory requirements Meeting regulatory requirements Concern with ligitation protection Business Risk Legal Risk Other Business Risk Security Risk Compliance Requirements Compliance Requirements Legal Risk Security Risk 0% 10% 20% 30% 40% 50% 60% Percent of Respondents Source: SNIA-100 Year Archive Requirements Survey, January 2007 2017 Storage Developer Conference SNIA All Rights Reserved. 8

2007 SNIA Survey (Cont.) Key Findings The problems of logical and physical retention Practitioners were struggling - information is at risk long-term Problems were real and generally understood Long term generally means over 10-15 years IT can manage to migrate and retain readability for about this long For longer periods, processes begin failing, become too costly, and the volume of information becomes overwhelming Long term retention requirements are real >80% of organizations reporting have a need to retain information over 50 yrs 68% report a need of over 100 yrs 2017 Storage Developer Conference SNIA All Rights Reserved. 9

10 Years Later Solutions are now becoming available Standards OAIS, VERS, MoReq, Storage formats - SIRF, OpenAXF, PREMIS, BagIt. Software Fedora, LOCKSS, DSPace, Arkivum, irods, Rosetta,. Cloud Services Preservica, Duracloud, Chronopolis, Dternity, Glacier,. But, their usage is still limited Primarily used in government agencies, libraries, & highly regulated industries Why aren t organizations using these solutions Lack of education or understanding Lack of: need, will, funding, penalties, etc. Short term focus 2017 Storage Developer Conference SNIA All Rights Reserved. 10

100 Year Archive Survey 2017 The LTR TWG and DPCO developed a new 100 Year Archive survey Focus will be on IT best practices, not just business requirements We will seek to survey the IT staff charged with long term retention requirements Need to assess the impact of the cloud The goal of this new survey is to assess Who needs to retain long term information What information needs to be retained, with appropriate policies Are organizations meeting their needs, have practices evolved in 10 years How is long term information is Stored systems, services, storage technology, etc. Secured encryption, access control, etc. Preserved migration, preservation formats, etc. 2017 Storage Developer Conference SNIA All Rights Reserved. 11

Emerging Changes Growth of the cloud Growth of SaaS preservation services Continued growth of data volume Migration from Content Addressable Storage to Object & WORM NAS Assessing the continued viability of tape & optical storage mediums Emergence of preservation strategies and formats Growth in the need (and regulation) for security and privacy 2017 Storage Developer Conference SNIA All Rights Reserved. 12

Target Respondents Primary target is IT staff associated with archives To get better information about systems and technologies Other respondents representing A business group Records and Information Management (RIM) Archive/Museum Academic/Scientist Library Security Legal Finance 2017 Storage Developer Conference SNIA All Rights Reserved. 13

Topics Covered Demographics Business Drivers Policies Sources Storage Practices/Experience Preservation Security/Privacy 2017 Storage Developer Conference SNIA All Rights Reserved. 14

Please Take the Survey! The Long Term Retention Technical Working Group and the Data Protection Committee are pleased to announce the release of the 2017 survey! We are now seeking the help of IT and archiving professionals to complete the new survey to help us understand How archive practices have evolved in the last ten years What type of information is now being retained and for how long Changes in corporate practices Impact of technology changes (e.g., cloud) Results to be published in early 2018 Please take the survey at: www.surveymonkey.com/r/100yrarchivesurvey 2017 Storage Developer Conference SNIA All Rights Reserved. 15

For Further Information Self-contained Information Retention Format (SIRF) For Future Semantic Interoperability http://ceur-ws.org/vol-1306/paper2.pdf SIRF specification: http://www.snia.org/tech_activities/standards/curr_standards/sirf More information on SIRF & SNIA LTR activities (including these slides): http://www.snia.org/ltr OpenSIRF is available at: http://github.com/opensirf LinkedIn SNIA Archive Survey group: https://www.linkedin.com/groups/8590697 2017 Storage Developer Conference SNIA All Rights Reserved. 16

Special Thanks The SNIA would like to thank the following individuals & groups for their contributions to the creation of this 100-Year Archive Survey 100-Year Archive Survey (2017) Contributors: Sam Fineberg Bob Rogers Paul Talbut Thomas Rivera Eric Hibbard Gene Nagle Michael Peterson Philip Viana Simona Cohen Lori Ashley Reagan Moore Mary Baker Mark Carlson Bill Martin SNIA - Long Term Retention Technical Working Group (LTR TWG) SNIA - Data Protection & Capacity Optimization (DPCO) Committee SNIA - Security Technical Working Group (Security TWG) 2017 Storage Developer Conference SNIA All Rights Reserved. 17