{
  "node_id": "nist-sp-800-209-storage-infrastructure",
  "title": "Security Guidelines for Storage Infrastructure",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2020-10-01",
  "bluf": "This document provides an overview of the evolution of the storage technology landscape, current security threats, and the resultant risks. The primary purpose is to provide a comprehensive set of security recommendations for the current landscape of storage infrastructure, which consists of a mixture of legacy and advanced systems. The recommendations and security focus areas span those that are common to the entire IT infrastructure, such as physical security, authentication and authorization, change management, configuration control, incident response, and recovery. Within these areas, security controls that are specific to storage technologies, such as network-attached storage (NAS) and storage area networks (SAN), are also covered. In addition, security recommendations specific to storage technologies are provided for the following areas of operation: data protection, isolation, restoration assurance, and encryption. The guidance applies to traditional storage services (block, file, and object), storage virtualization, storage architectures for virtualized server environments, and storage resources hosted in the cloud.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-53-r5",
    "nist-sp-800-63b-authentication"
  ],
  "primary_citations_count": 7
}