<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Charlotte Letamendia, Author at OVHcloud Blog</title>
	<atom:link href="https://blog.ovhcloud.com/author/charlotte-letamendia/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.ovhcloud.com/author/charlotte-letamendia/</link>
	<description>Innovation for Freedom</description>
	<lastBuildDate>Fri, 21 Apr 2023 16:39:24 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://blog.ovhcloud.com/wp-content/uploads/2019/07/cropped-cropped-nouveau-logo-ovh-rebranding-32x32.gif</url>
	<title>Charlotte Letamendia, Author at OVHcloud Blog</title>
	<link>https://blog.ovhcloud.com/author/charlotte-letamendia/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>5 ground rules to secure your storage</title>
		<link>https://blog.ovhcloud.com/5-ground-rules-to-secure-your-storage/</link>
		
		<dc:creator><![CDATA[Charlotte Letamendia]]></dc:creator>
		<pubDate>Fri, 21 Apr 2023 16:39:01 +0000</pubDate>
				<category><![CDATA[OVHcloud Engineering]]></category>
		<category><![CDATA[DevOps]]></category>
		<category><![CDATA[ObjectStorage]]></category>
		<category><![CDATA[OVHcloud]]></category>
		<category><![CDATA[S3]]></category>
		<guid isPermaLink="false">https://blog.ovhcloud.com/?p=24848</guid>

					<description><![CDATA[My data is an asset. Let&#8217;s share the best practices&#160;to protect your data. If you feel that security is a constraint, it’s time to think again! In this blog post, I will share with you 5 simple rules that can be easily implemented to secure your back-ups without headache thanks to the &#8220;Objects Storage Standard-S3 API&#8221; [&#8230;]<img src="//blog.ovhcloud.com/wp-content/plugins/matomo/app/matomo.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Fblog.ovhcloud.com%2F5-ground-rules-to-secure-your-storage%2F&amp;action_name=5%20ground%20rules%20to%20secure%20your%20storage&amp;urlref=https%3A%2F%2Fblog.ovhcloud.com%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" />]]></description>
										<content:encoded><![CDATA[
<h3 class="wp-block-heading">My data is an asset. Let&#8217;s share the best practices&nbsp;to protect your data.</h3>



<p>If you feel that security is a constraint, it’s time to think again! In this blog post, I will share with you <strong>5 simple rules</strong> that can be easily implemented to secure your back-ups without headache thanks to the &#8220;<strong>Objects Storage Standard-S3 API&#8221;</strong> class of storage.</p>



<figure class="wp-block-image aligncenter size-large is-resized"><img fetchpriority="high" decoding="async" src="https://blog.ovhcloud.com/wp-content/uploads/2023/04/IMG_1504-1024x538.jpg" alt="" class="wp-image-25167" width="512" height="269" srcset="https://blog.ovhcloud.com/wp-content/uploads/2023/04/IMG_1504-1024x538.jpg 1024w, https://blog.ovhcloud.com/wp-content/uploads/2023/04/IMG_1504-300x158.jpg 300w, https://blog.ovhcloud.com/wp-content/uploads/2023/04/IMG_1504-768x404.jpg 768w, https://blog.ovhcloud.com/wp-content/uploads/2023/04/IMG_1504.jpg 1199w" sizes="(max-width: 512px) 100vw, 512px" /></figure>



<p><em>I am <strong>DevOps</strong> or <strong>DevSecOps</strong>, I am developing on my platform and want to stay concentrated on my business where I have added value. That is why I am managing by code the deployment and scale of my infrastructures.   I am delegating the management of my infrastructure to my cloud provider.</em></p>



<p><em>While developing my business, the volume of my data grows exponentially,  so my data has value too!</em></p>



<p><em>As my business grows, I collect more data and keep a historical set year after year. I am even deploying in new locations around the world! </em></p>



<p><em>All this data (applications, user data, logs, media, analytics, reporting) are stored and backed up in object storage for flexibility, metadata search, and easy scale. My data represents a great asset in my hand. Data drives my business and I want to protect it.</em></p>



<figure class="wp-block-image aligncenter size-large is-resized"><img decoding="async" src="https://blog.ovhcloud.com/wp-content/uploads/2023/03/blogpostObjectStorage01-1024x538.png" alt="" class="wp-image-24849" width="768" height="404" srcset="https://blog.ovhcloud.com/wp-content/uploads/2023/03/blogpostObjectStorage01-1024x538.png 1024w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/blogpostObjectStorage01-300x158.png 300w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/blogpostObjectStorage01-768x403.png 768w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/blogpostObjectStorage01-1536x807.png 1536w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/blogpostObjectStorage01-2048x1076.png 2048w" sizes="(max-width: 768px) 100vw, 768px" /></figure>



<h4 class="wp-block-heading" id="BlogPostBackupOffsite-Dataisabugassetthatrequiregoodgovernance!">Data is an important asset that requires good governance!&nbsp;</h4>



<p>Please don&#8217;t think, &#8220;cool I have copied my data to a secondary bucket, my backup is complete, I am safe.&#8221; Nope, this is not OK!&nbsp;</p>



<p>What S3 Object Storage doesn’t protect you from is&nbsp;<em>yourself</em>. Let&#8217;s take a look together at the 3 types of risks we need to protect ourselves from.</p>



<p>(1) The number one factor for data loss is human error, accidental deletion, or the overwriting of an object with garbage data. This is a scenario that you want to avoid.</p>



<p>(2) The second category relates to <strong>unpredictable events</strong>: software issues, hardware issues (drive failure), datacenter downtime, or natural/manmade disaster.&nbsp;</p>



<p>(3) The third category is&nbsp;the stuff that causes security experts to lose sleep at night-<strong>malicious actions</strong>: malware, ransomware &amp; viruses, acts of sabotage, DDoS&#8230;</p>



<p>Security is important and non-negotiable, let&#8217;s take a look at <strong>5&nbsp;easy rules</strong>&nbsp;to protect against these risks.</p>



<p>&#8230;and continue to work&nbsp;in all serenity!</p>



<h3 class="wp-block-heading">Rule n° 1 &#8211; versioning</h3>



<p>Versioning helps to protect against accidental overwriting. You can reverse a version after accidental deletion or retrieve a specific version in the event of data corruption.</p>



<p></p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="95" src="https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage02-1024x95.png" alt="" class="wp-image-24850" srcset="https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage02-1024x95.png 1024w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage02-300x28.png 300w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage02-768x71.png 768w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage02-1536x142.png 1536w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage02-2048x189.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading">Rule n° 2 &#8211; immutability</h3>



<p>When your primary storage systems must be open and available, your&nbsp;backup data should be isolated and immutable.&nbsp;</p>



<p>Implement the Write&nbsp;Once,&nbsp;Read&nbsp;Many (WORM) model using S3 object lock API.&nbsp;</p>



<p>You can define different parameters according to your needs, business, and type of data:</p>



<ul class="wp-block-list">
<li>retention periods&nbsp;</li>



<li>legal mode</li>



<li>governance mode</li>



<li>compliance mode</li>
</ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="93" src="https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage03-1024x93.png" alt="" class="wp-image-24851" srcset="https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage03-1024x93.png 1024w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage03-300x27.png 300w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage03-768x70.png 768w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage03-1536x139.png 1536w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage03-2048x185.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>This rule helps your organization to respect compliance. To keep logs for a legally limited period, the “compliance mode” will help you set the duration needed. It’s quite handy because logs are generated every second so it can be difficult to keep track. With compliant mode, you don’t need to worry about this anymore, you can set a period of 1, 3, or 5 years and the logs will remain protected throughout the designated period.</p>



<p>read more:&nbsp;<a href="https://docs.ovh.com/ie/en/storage/object-storage/s3/managing-object-lock/" data-wpel-link="exclude">https://docs.ovh.com/ie/en/storage/object-storage/s3/managing-object-lock/</a></p>



<h3 class="wp-block-heading"><strong>Rules n°3 &#8211; data replication off-site</strong></h3>



<p>To be protected against hardware failure issues or geographical events, follow the well-known model : 3+2+1</p>



<p>Before setting your copies of data, you need to evaluate the RPO and RTO of your target&nbsp;</p>



<ul class="wp-block-list">
<li>RPO (real point objective) =&nbsp;in case of geographical failure, what is &#8211; in time &#8211; the most recent snapshot of your data that is acceptable for you to restore your data while losing the minimum amount of data</li>



<li>RTO (real time objective) = in case of geographical failure, what is the acceptable time to recover your data&nbsp;</li>
</ul>



<figure class="wp-block-image aligncenter size-full"><img loading="lazy" decoding="async" width="640" height="960" src="https://blog.ovhcloud.com/wp-content/uploads/2023/04/storage.jpg" alt="data replication off-site" class="wp-image-25165" srcset="https://blog.ovhcloud.com/wp-content/uploads/2023/04/storage.jpg 640w, https://blog.ovhcloud.com/wp-content/uploads/2023/04/storage-200x300.jpg 200w" sizes="auto, (max-width: 640px) 100vw, 640px" /></figure>



<p>Of course, everybody wants a 0-second recovery, but is it necessary?</p>



<p>Such a recovery plan requires costly resources to maintain. Good advice is to&nbsp;sort your data by category of criticality and fine-tune this plan by categories and put into place backup retention policies</p>



<figure class="wp-block-table is-style-regular"><table><thead><tr><th>Type</th><th>Back up policies</th></tr></thead><tbody><tr><td>Nonbusiness critical&nbsp;</td><td>Weekly&nbsp;</td></tr><tr><td>Business critical</td><td>Every day for 1 month then monthly during 1 year</td></tr><tr><td>Archive</td><td>&gt; 1 year</td></tr></tbody></table></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="89" src="https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage05-1024x89.png" alt="" class="wp-image-24853" srcset="https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage05-1024x89.png 1024w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage05-300x26.png 300w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage05-768x67.png 768w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage05-1536x134.png 1536w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage05-2048x178.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>read more :&nbsp;<a href="https://docs.ovh.com/ie/en/storage/object-storage/s3/rclone/" data-wpel-link="exclude">https://docs.ovh.com/ie/en/storage/object-storage/s3/rclone/</a></p>



<h3 class="wp-block-heading">Rules n°4 &#8211; encryption</h3>



<p>When your data is not used you can cipher it with your own key. We use a feature based on the AES-256 protocol.</p>



<p>Encrypt your data: using your own keys and encryption based on AES-256&nbsp;</p>



<p>Note that the data in transit is encrypted thanks to the TLS protocol.</p>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage06-1024x75.png" alt="" class="wp-image-24854" width="1024" height="75" srcset="https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage06-1024x75.png 1024w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage06-300x22.png 300w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage06-768x56.png 768w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage06-1536x112.png 1536w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage06-2048x149.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>read more :&nbsp;<a href="https://docs.ovh.com/ie/en/storage/object-storage/s3/encrypt-your-objects-with-sse-c/" data-wpel-link="exclude">https://docs.ovh.com/ie/en/storage/object-storage/s3/encrypt-your-objects-with-sse-c/</a></p>



<h3 class="wp-block-heading">Rules n°5 &#8211; user policies&nbsp;</h3>



<p>Grant only the permissions that are required to perform a task using&nbsp;</p>



<ul class="wp-block-list">
<li>User policy</li>



<li>Bucket policy (soon)</li>



<li>Bucket ACL</li>
</ul>



<p>Extract your S3 policies every month and check them; It will not take too much time and can be automized. Verify that you know all users and that the rights are adapted to each profile. Never let a wildcard * provide access to all to a sensible bucket/object.</p>



<figure class="wp-block-image aligncenter size-full is-resized is-style-default"><img loading="lazy" decoding="async" src="https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage07.png" alt="" class="wp-image-24855" width="308" height="272" srcset="https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage07.png 774w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage07-300x265.png 300w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage07-768x679.png 768w" sizes="auto, (max-width: 308px) 100vw, 308px" /></figure>



<p>read more:&nbsp;<a href="https://docs.ovh.com/ie/en/storage/object-storage/s3/identity-and-access-management/" data-wpel-link="exclude">https://docs.ovh.com/ie/en/storage/object-storage/s3/identity-and-access-management/</a></p>



<p><strong>Be uncompromising in the implementation of security compliance.</strong></p>



<p>If you are comfortable with these 5 rules you can rest assured. As for all security rules, a regular check-up/training is always useful!&nbsp;</p>



<h3 class="wp-block-heading"><strong>Bonus rule &#8211; Traceability&nbsp;&nbsp;</strong></h3>



<p>When you are audited or you want to audit your architecture of your cloud provider it is important to have all the elements you need.</p>



<p>The S3 logging feature will help you provide the traceability needed in order to know who, when, and why data was accessed.</p>



<p>Thanks to our API, you can set up some triggers in order to be alerted in case of bad or simply abnormal behavior.</p>



<figure class="wp-block-image aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage08-1-1024x595.png" alt="" class="wp-image-24884" width="512" height="298" srcset="https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage08-1-1024x595.png 1024w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage08-1-300x174.png 300w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage08-1-768x447.png 768w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage08-1-1536x893.png 1536w, https://blog.ovhcloud.com/wp-content/uploads/2023/03/BlogpostObjectStorage08-1-2048x1191.png 2048w" sizes="auto, (max-width: 512px) 100vw, 512px" /></figure>



<h2 class="wp-block-heading">Want to know more about data protection? More blog posts are coming soon!</h2>



<p>Meanwhile, feel free to consult our guides that will assist you in your data security implementation.</p>



<p>And discover OVHcloud Object Storage services with S3 API&nbsp;<a href="https://www.ovhcloud.com/en-ie/public-cloud/object-storage/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">https://www.ovhcloud.com/en-ie/public-cloud/object-storage/</a></p>



<figure class="wp-block-table"><table><thead><tr><th>Who are you?</th><th>Guides</th></tr></thead><tbody><tr><td>Data protection for<br><strong>SysAdmin&nbsp;</strong></td><td>VMware user ?&nbsp;<br><a href="https://docs.ovh.com/ie/en/storage/object-storage/s3/veeam/" data-wpel-link="exclude">https://docs.ovh.com/ie/en/storage/object-storage/s3/veeam/</a><br>Nutanix user ?&nbsp;<br><a href="https://docs.ovh.com/ie/en/nutanix/hycu-backup/" data-wpel-link="exclude">https://docs.ovh.com/ie/en/nutanix/hycu-backup/</a><br><a href="https://docs.ovh.com/ie/en/nutanix/nutanix-veeam-backup/" data-wpel-link="exclude">https://docs.ovh.com/ie/en/nutanix/nutanix-veeam-backup/</a></td></tr><tr><td>Data protection <strong>with infrastructure as code</strong></td><td>Kubernetes user ?&nbsp;<br><a href="https://docs.ovh.com/fr/kubernetes/backing-up-cluster-with-velero/" data-wpel-link="exclude">https://docs.ovh.com/fr/kubernetes/backing-up-cluster-with-velero/</a><br><a href="https://docs.ovh.com/ie/en/kubernetes/backup-and-restore-cluster-namespace-and-applications-with-trilio/#how-triliovault-for-kubernetes-works" data-wpel-link="exclude">https://docs.ovh.com/ie/en/kubernetes/backup-and-restore-cluster-namespace-and-applications-with-trilio/#how-triliovault-for-kubernetes-works</a></td></tr><tr><td>&nbsp;Data protection for<br><strong>Developpers</strong></td><td>S3 API user ?&nbsp;<br><a href="https://docs.ovh.com/ie/en/storage/object-storage/s3/managing-object-lock/" data-wpel-link="exclude">https://docs.ovh.com/ie/en/storage/object-storage/s3/managing-object-lock/</a><br><a href="https://docs.ovh.com/ie/en/storage/object-storage/s3/rclone/" data-wpel-link="exclude">https://docs.ovh.com/ie/en/storage/object-storage/s3/rclone/</a><br><a href="https://docs.ovh.com/ie/en/storage/object-storage/s3/encrypt-your-objects-with-sse-c/" data-wpel-link="exclude">https://docs.ovh.com/ie/en/storage/object-storage/s3/encrypt-your-objects-with-sse-c/</a><br><a href="https://docs.ovh.com/ie/en/storage/object-storage/s3/identity-and-access-management/" data-wpel-link="exclude">https://docs.ovh.com/ie/en/storage/object-storage/s3/identity-and-access-management/</a><br><a href="https://docs.ovh.com/fr/storage/object-storage/s3/bucket-acl/" data-wpel-link="exclude">https://docs.ovh.com/fr/storage/object-storage/s3/bucket-acl/</a><br><a href="https://docs.ovh.com/fr/storage/object-storage/s3/server-access-logging/" data-wpel-link="exclude">https://docs.ovh.com/fr/storage/object-storage/s3/server-access-logging/</a></td></tr></tbody></table></figure>
<img loading="lazy" decoding="async" src="//blog.ovhcloud.com/wp-content/plugins/matomo/app/matomo.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Fblog.ovhcloud.com%2F5-ground-rules-to-secure-your-storage%2F&amp;action_name=5%20ground%20rules%20to%20secure%20your%20storage&amp;urlref=https%3A%2F%2Fblog.ovhcloud.com%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" />]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
