A international maritime logistics enterprise operates edge storage appliances at remote port facilities to handle offline container manifest data. The security architecture team must ensure that if storage drives are physically stolen from an unattended facility, the data at rest cannot be extracted. Additionally, key lifecycle management must be centralized without relying on local site administrators to manually unlock storage volumes after a system reboot. Which of the following storage security architectures best meets these requirements?
- Self-Encrypting Drives (SEDs) integrated with an enterprise Key Management Interoperability Protocol (KMIP) serverAnswer
- BSoftware-based RSA asymmetric bulk encryption applied to all local storage partition blocks
- CTransport Layer Security (TLS) tunnel encapsulation configured between the edge storage appliances and central servers
- DEndpoint Data Loss Prevention (DLP) agents restricting file copying to unauthorized USB mass storage devices
Answer
Self-Encrypting Drives (SEDs) integrated with an enterprise Key Management Interoperability Protocol (KMIP) server
Self-Encrypting Drives (SEDs) perform low-level hardware cryptographic operations directly on the drive controller, ensuring that data is completely inaccessible if physical drives are detached or stolen. Connecting SEDs to a centralized Key Management Interoperability Protocol (KMIP) server enables centralized key management and automated, secure authentication during remote appliance booting without requiring local administrator password entry.
Step-by-Step Solution
Key Concept
Data Protection at Rest and Centralized Storage Key Management