Why Storage Security is a Foundation-Layer Priority
Storage systems — SAN, NAS, object storage, cloud volumes, and backup media — contain the most valuable and regulated data in the enterprise. Yet in a typical Indian enterprise security assessment, storage controls receive far less attention than network perimeter defences, despite holding orders of magnitude more sensitive data. The DPDP Act 2023 Section 8(4) requires data fiduciaries to maintain the completeness, accuracy, and consistency of personal data. ISO/IEC 27001:2022 Annex A.8.24 requires the use of cryptography for data protection, including data at rest. The RBI Master Direction on IT explicitly mandates encryption of sensitive financial data at rest.
Storage Security Control Matrix
| Control | SAN/NAS | Cloud Storage | Backup Media |
|---|---|---|---|
| Encryption at rest | AES-256 disk/volume | SSE-S3 / SSE-KMS | AES-256, key mgmt |
| Access control | Zoning + LUN masking | IAM policies + bucket ACL | Often missing |
| Access logging | Rarely enabled | S3 access logs | Rarely enabled |
| Secure disposal | DoD wipe + cert | Provider destruction cert | Physical shredding needed |
| Immutability | WORM not configured | S3 Object Lock | Not implemented |
Key Encryption at Rest Requirements
Encryption at rest protects data from physical theft of storage media and from insider threats with physical access but without logical access. Minimum standard: AES-256 encryption for all storage volumes containing personal data (DPDP) or confidential business data. Key management is as important as encryption itself — keys must be stored separately from encrypted data, rotated annually, and managed using a dedicated Key Management Service (KMS). Cloud environments: use AWS KMS, Azure Key Vault, or Google Cloud KMS with customer-managed keys (CMEK) for regulated data.
Audit Trail Requirements for Storage Access
Who accessed what data, when, and what they did with it — this is the audit trail requirement. CERT-In requires organisations to maintain logs for a minimum of 180 days. DPDP Act 2023 requires the ability to demonstrate lawful processing. Enable storage access logging for all volumes containing personal, financial, or sensitive business data. Forward logs to SIEM. Alert on anomalous bulk-read operations (potential exfiltration) and access outside business hours from unusual locations.
Storage Security Assessed in Every IGaaS Engagement
InfraVeritas 360 assesses encryption at rest coverage, access control configuration, storage audit logging, and disposal procedures — mapping every gap to DPDP, ISO 27001, and CERT-In requirements.
Assess Your Storage Security →