Storage Security Foundation: Encryption, Access Controls, and Audit Trails for Indian Enterprises

By Deepika Nair · 21 April 2026

Why Storage Security is a Foundation-Layer Priority

Storage systems — SAN, NAS, object storage, cloud volumes, and backup media — contain the most valuable and regulated data in the enterprise. Yet in a typical Indian enterprise security assessment, storage controls receive far less attention than network perimeter defences, despite holding orders of magnitude more sensitive data. The DPDP Act 2023 Section 8(4) requires data fiduciaries to maintain the completeness, accuracy, and consistency of personal data. ISO/IEC 27001:2022 Annex A.8.24 requires the use of cryptography for data protection, including data at rest. The RBI Master Direction on IT explicitly mandates encryption of sensitive financial data at rest.

Storage Security Control Matrix

ControlSAN/NASCloud StorageBackup Media
Encryption at restAES-256 disk/volumeSSE-S3 / SSE-KMSAES-256, key mgmt
Access controlZoning + LUN maskingIAM policies + bucket ACLOften missing
Access loggingRarely enabledS3 access logsRarely enabled
Secure disposalDoD wipe + certProvider destruction certPhysical shredding needed
ImmutabilityWORM not configuredS3 Object LockNot implemented

Key Encryption at Rest Requirements

Encryption at rest protects data from physical theft of storage media and from insider threats with physical access but without logical access. Minimum standard: AES-256 encryption for all storage volumes containing personal data (DPDP) or confidential business data. Key management is as important as encryption itself — keys must be stored separately from encrypted data, rotated annually, and managed using a dedicated Key Management Service (KMS). Cloud environments: use AWS KMS, Azure Key Vault, or Google Cloud KMS with customer-managed keys (CMEK) for regulated data.

Audit Trail Requirements for Storage Access

Who accessed what data, when, and what they did with it — this is the audit trail requirement. CERT-In requires organisations to maintain logs for a minimum of 180 days. DPDP Act 2023 requires the ability to demonstrate lawful processing. Enable storage access logging for all volumes containing personal, financial, or sensitive business data. Forward logs to SIEM. Alert on anomalous bulk-read operations (potential exfiltration) and access outside business hours from unusual locations.

Storage Security Assessed in Every IGaaS Engagement

InfraVeritas 360 assesses encryption at rest coverage, access control configuration, storage audit logging, and disposal procedures — mapping every gap to DPDP, ISO 27001, and CERT-In requirements.

Assess Your Storage Security →