Protection from a Compromised Account

Ops Center Protector User Guide

Version
7.7.x
Audience
anonymous
Part Number
MK-99PRT002-08
ft:lastEdition
2023-10-26

It is possible that an account within the backup system could be compromised. E.g.through social engineering , a bad actor, etc. To mitigate this the following best practices can be employed:

  • Protector has a very granular RBAC system. It not only defines the what roles as user can have but also roles against resources. So a user that may have complete control of certain assets within a system and may have no control or even visibility of other assets within Protector's inventory. By limiting access to the minimum level that is required for someone who has an account within Protector, it is possible to limit the scope of what that account can do if it is compromised. You can for instance give a user access to use an array within Protector but not give them administrative rights.
  • Use of hardware Data Retention Utility (DRU) to lock down backups for a given period of time. DRU protected storage cannot be modified and is akin to be putting data in a time locked safe. This allows a company's assets to be protected for a timeframe suitable for the detection of an intrusion.
  • Backups to HCP, a WORM object store, where you can archive lock data is another suitable solution for host based backups.