Immutable Storage

Overview

Recovery plans must include data protection and retrievability. Cyberattacks of any kind can cost companies immense value in lost revenue, reputation and client trust.

(Undefined variable: Series/User_Guide_Online_Help.product_generic) offers two immutable storage features: Secure Snapshots and Retention Lock.

What is Immutable Storage?

Immutable storage is a data security technology that prevents stored information from being modified, overwritten, or deleted for a set period. Often referred to as WORM (Write Once, Read Many), it ensures that once data is written, it remains in its original, pristine state, making it a critical defense against ransomware and accidental data loss.

Benefits of immutable storage include:

What is Ransomware?

Ransomware is a category of cyberattack malware that infects a computer system and restricts access, demanding a ransom to be paid to the malware's creator. Some ransomware encrypts hard drive files. Other types lock the system and display messages requesting payment.

Secure Snapshots

(Undefined variable: Series/User_Guide_Online_Help.product_generic) Secure Snapshots is a simple-to-use, cost-effective feature that allows you to retain and restore complete, secure, incorruptible point-in-time copies of data on your system. This process begins with enabling snapshots for your entire system, then enabling them individually for specific shares, partitions or LSUs, and setting retention periods.

Frequently Asked Questions

Q: What are Secure Snapshots?

A: (Undefined variable: Series/User_Guide_Online_Help.product_generic) Secure Snapshots enable users to create point-in-time physical copies, or snapshots, of the shares, partitions, or LSUs. Each snapshot is timestamped, secured and isolated in a non-network-addressable blockpool located in the (Undefined variable: Series/User_Guide_Online_Help.product_generic) system, enabling fast recovery from ransomware attacks.

 

Q: What is the difference between Secure Snapshots and Retention Lock?

A: Secure Snapshot allows to system-level immutability at a given point of time. This allows you to retain copies of shares, partitions, and settings on your system. Retention Lock allow file-level immutability within NAS shares. Once a file has a retention lock, it cannot be altered or deleted until the configured lock time period has expired.

 

Q: How do Secure Snapshots Ensure Security?

A: Snapshots cannot be deleted or changed. There is no datapath access to a snapshot. Attackers cannot use generic attacks on the mounted backup file system, nor can they use the (Undefined variable: Series/User_Guide_Online_Help.product_generic) GUI or RestAPI to access and delete snapshots. There are no referenceable pointers or links to the snapshots or their location to be discovered or otherwise obtained by malware attackers. Data retention is set by the user. Snapshots are only deleted on their set expiration date, which can be individually selected and extended. No interface is provided to access or delete the shares, partitions, or LSUs in the snapshot.

With (Undefined variable: Series/User_Guide_Online_Help.product_generic) Secure Snapshots users are always in control of their data security and retrieveability.

 

Q: How do (Undefined variable: Series/User_Guide_Online_Help.product_generic) Systems Create Secure Snapshots?

A: After they are enabled for the system then for individual shares, partitions, or LSUs, snapshots are created manually using Command Line Interface (CLI) commands or in the (Undefined variable: Series/User_Guide_Online_Help.product_generic) GUI, using the Scheduler. The (Undefined variable: Series/User_Guide_Online_Help.product_generic) makes a copy of the enabled shares, VTL partitions, or OST LSUs, to be retained for a set period of time.

See Enabling Secure Snapshots for instructions on how to get started enabling the feature and scheduling snapshots in the (Undefined variable: Series/User_Guide_Online_Help.product_generic) User Interface (UI), for specific shares, VTLs or OST LSUs. See Manage Secure Snapshots in (Undefined variable: Series/User_Guide_Online_Help.product_generic) Command Line Interface (CLI) to use Secure Snapshot CLI commands.

 

Q: How do Users Recover Snapshot Data?

A: A point-in-time snapshot is identified and restored from the GUI, restoring the share, partition, or LSU to its state before the attack. This latest uncorrupted snapshot is unpacked into a new share, partition, or LSU, with either the original name or a new name. Snapshots to be recovered are selected by the customer per their analysis of the attack on their business.

You can restore snapshots in the (Undefined variable: Series/User_Guide_Online_Help.product_generic) User Interface (UI) on specific shares, VTL partitions or OST LSUs. See Manage Secure Snapshots in (Undefined variable: Series/User_Guide_Online_Help.product_generic) Command Line Interface (CLI) to use Secure Snapshot CLI commands.

Tasks

The processes for enabling and scheduling secure snapshots is detailed in the following topics:

  1. Enabling Systemwide Secure Snapshots
  2. Enabling Secure Snapshots for Individual Shares
  3. Scheduling Secure Snapshot Events
  4. Viewing and Modifying Secure Share Snapshots
  5. Viewing and Modifying VTL Partition Snapshots
  6. Viewing and Modifying OST LSU Snapshots

Retention Lock

Retention Lock is a data protection feature that enforces immutability at the file level. It ensures that once a backup file is written, it cannot be altered or deleted until its specified retention period expires.

Note: The retention lock feature is currently available for individual files within a NAS share using the NFS protocol with deduplication enabled.

Frequently Asked Questions

Q: What is the difference between Secure Snapshots and Retention Lock?

A: Secure Snapshot allows to system-level immutability at a given point of time. This allows you to retain copies of shares, partitions, and settings on your system. Retention Lock allow file-level immutability within NAS shares. Once a file has a retention lock, it cannot be altered or deleted until the configured lock time period has expired.

 

Q: Does Retention Lock support regulatory compliance?

A: Retention Lock meets and supports the following regulatory standards: SEC 17a-4(f), CFTC Rule 1.31b, FDA 21 CFR Part 11, Sarbanes-Oxley Act, IRS 98025 and 97-22, ISO Standard 15489-1, and MoREQ2010.

Tasks

The processes for enabling and applying retention lock to NAS files is detailed in the following topics:

  1. View Retention Lock Status

  2. Enable Retention Lock on a NAS Share

  3. Enable Retention Lock on Files within a NAS Share

  4. Unlock Retention Files within a NAS Share