Author Topic: Does OD support storing encryted documents?  (Read 2994 times)

cleach

  • Guest
Does OD support storing encryted documents?
« on: July 25, 2011, 03:03:38 PM »
Does OD support the automatic entrytpion of documents as they are loaded and later their decryption for viewing them?

And if supported, would the cache also be encrypted?

Due to all the sensitive information being stored in OD, there is concern about having everything stored in clear text if we get a security breach.

Justin Derrick

  • IBM Content Manager OnDemand Consultant
  • Administrator
  • Hero Member
  • *****
  • Posts: 2230
  • CMOD Guru for hire...
    • View Profile
    • Tenacious Consulting
Re: Does OD support storing encryted documents?
« Reply #1 on: July 26, 2011, 08:55:58 AM »
Hi Curtis.

Just as a follow up, data in the cache and TSM is stored with a proprietary compression method.  Even an advanced user with non-CMOD-specific knowledge would have difficulty in successfully decompressing an entire stream of data.  (Heck, even I have trouble with it some days.)

Now, this is not truly secure, as there is no authentication or encryption, but you don't have to worry so much about the data being stored 'in the clear'.

The database information, however, IS stored in a format that could be parsed by an advanced-level adversary.  There is a database encryption product (formerly known as "Vormetric") that encrypts data at the filesystem level.

While application security is important, more straightforward methods at other levels (strict firewalls, restricting available network services, hardening the operating system) will work as far more effectiveness against hackers.
IBM CMOD Professional Services: http://TenaciousConsulting.com
Call:  +1-866-533-7742  or  eMail:  jd@justinderrick.com
IBM CMOD Wiki:  https://CMOD.wiki/
FREE IBM CMOD Education & Webinars:  https://CMOD.Training/

Interests: #AIX #Linux #Multiplatforms #DB2 #TSM #SP #Performance #Security #Audits #Customizing #Availability #HA #DR