EN ISO/IEC 27040:2016
Information technology - Security techniques - Storage security

Standard No.
EN ISO/IEC 27040:2016
Release Date
2016
Published By
European Committee for Standardization (CEN)
Latest
EN ISO/IEC 27040:2016
Replace
FprEN ISO/IEC 27040:2016
Scope
This International Standard provides detailed technical guidance on how organizations can implement appropriate risk mitigation by applying a proven and consistent approach to planning, designing, documenting and implementing data storage security. Storage security refers, on the one hand, to the protection (security) of information at its storage location and to the security of the information when transmitted via the communication interfaces in connection with storage. Storage security concerns the security of devices and media, the security of management activities related to those devices and media, the security of applications and services, and the security for the end user during the life of those devices and media and after their useful life. Storage security is important to anyone who owns, operates, or uses data storage devices, disks, and storage networks. In addition to executives and administrators who have specific responsibilities for information security, storage security, or storage operations, or who are responsible for developing an organization's overall security program and security policy, this does not include senior executives, purchasers of storage products and services, and others technical managers or users. It is also important to anyone involved in the planning, design, and implementation of architectural aspects of storage network security. This International Standard provides an overview of storage security concepts and their associated definitions. It provides guidance on the threat, design and control aspects associated with typical storage scenarios and areas of storage technologies. It also refers to other International Standards and Technical Reports that address existing practices and techniques that can be applied for storage security purposes.

EN ISO/IEC 27040:2016 Referenced Document

  • ANSI/INCITS 458-2011 Information technology - SCSI Object-Based Storage Device Commands -2 (OSD-2)*2024-04-20 Update
  • ANSI/INCITS 461-2010 Information technology - Fibre Channel - Switch Fabric - 5 (FC-SW-5)
  • ANSI/INCITS 462-2010 Information technology - Fibre Channel - Backbone - 5 (FC-BB-5)*2024-04-20 Update
  • ANSI/INCITS 463-2010 Information technology - Fibre Channel - Generic Services - 6 (FC-GS-6)
  • ANSI/INCITS 470-2011 Information technology - Framing and Signaling - 3 (FC-FS-3)*2024-04-20 Update
  • ANSI/INCITS 482-2012 Information technology - ATA/ATAPI Command Set - 2 (ACS-2)
  • ANSI/INCITS 496-2012 Information Technology - Fibre Channel - Security Protocols (FC-SP-2)*2024-04-20 Update
  • ISO 7498-2:1989 Information processing systems; Open Systems Interconnection; basis reference model; Part 2: Security architecture
  • ISO Guide 73:2009 Risk management - Vocabulary
  • ISO/IEC 10116:2006 Information technology - Security techniques - Modes of operation for an n-bit block cipher
  • ISO/IEC 11179-1:2004 Information technology - Metadata registries (MDR) - Part 1: Framework
  • ISO/IEC 11770-1:2010 Information technology - Security techniques - Key management - Part 1: Framework
  • ISO/IEC 11770-2:2008 Information technology - Security techniques - Key management - Part 2: Mechanisms using symmetric techniques
  • ISO/IEC 11770-3:2008 Information technology - Security techniques - Key management - Part 3: Mechanisms using asymmetric techniques
  • ISO/TR 10255:2009 Document management applications - Optical disk storage technology, management and standards

EN ISO/IEC 27040:2016 history




Copyright ©2024 All Rights Reserved