Physical security of backup tapes is essential for any business. If tapes are somehow lost or stolen, data must not be accessible without the proper authority. NetBackup allows administrators to centrally manage and track the encryption of backup data from within the NetBackup policy. By using software as the controller of encryption, rather than hardware, administrators gain a heterogeneous security option that allows them to encrypt and decrypt data regardless of the hardware platform used for backup or recovery.
NetBackup Client Encryption Option
Client encryption is now standard with every NetBackup client. This feature encrypts data during the backup process using a keyfile created by an administrator with a pass-phrase. Data remains encrypted while in transit and on the target media. On restores, the encrypted data is read from media and transferred across the network to the client where the the keyfile is used to decrypt the data.
NetBackup Media Server Encryption Option
Ensure that tapes being transported offsite cannot be read in the event they are lost, mishandled, or stolen. MSEO provides maximum flexibility and performance by providing parallelized and selectable encryption and compression and "set it and forget it" key management. Some key benefits include:
- Easier management and control. Encrypt within the Veritas NetBackup policy, eliminating a separate process or an extra dedicated device to manage.
- Maximum flexibility. Choose what data you want to encrypt and then choose the appropriate compression and encryption strength (AES 128-bit or AES 256-bit).
- Support for most common backup configurations. Includes support for disk staging to tape, the creation of tape copies for offsite purposes, and the backup of NAS devices (via NDMP).