{"id":3625,"date":"2024-12-04T08:24:57","date_gmt":"2024-12-04T07:24:57","guid":{"rendered":"https:\/\/wpethzprd.ethz.ch\/its\/?p=3625"},"modified":"2024-12-04T08:24:59","modified_gmt":"2024-12-04T07:24:59","slug":"categorisation-to-protect-tiered-data-protection","status":"publish","type":"post","link":"https:\/\/blogs.ethz.ch\/its\/2024\/12\/04\/categorisation-to-protect-tiered-data-protection\/","title":{"rendered":"Categorisation to protect: Tiered data protection"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">With malicious cyber attacks on the rise, every organisation needs to act and protect its data. To optimise resources, only critical and vital data must be protected with the highest levels of security and redundancy, while less important data can just be given standard protection. The key is to understand which data is vital and which is merely important. ETH has developed a protection strategy based on four data tiers, with Tier 1 at the top and Tier 4 at the bottom of the &#171;importance pyramid&#187;.<\/p>\n\n\n\n<!--more-->\n\n\n\n<p class=\"wp-block-paragraph\">Today&#8217;s threats to institutional data (both academic and administrative data) are increasing in severity and frequency. Research shows that ransomware attacks and other malicious cyber attacks are affecting many educational institutions around the world. ETH, as a top university, is an obvious potential target, and the risk of reputational damage and functional impairment from such attacks is real and significant.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Protection of the most important ETH data<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To mitigate the consequences of such scenarios, we must take action and protect our most important data as best we can. ETH Zurich&#8217;s IT Services are running projects aimed at preventing such events and improving resilience if they do occur.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As financial and human resources are limited for all organisations, the focus must be on protecting only the most valuable and critical data with the highest level of security and redundancy, while less important data can get by with fewer resources. In this way, the allocation of resources is optimised.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Improved resilience of data through categorisation in tiers<\/h2>\n\n\n\n<figure class=\"wp-block-image size-post-size\"><a href=\"https:\/\/blogs.ethz.ch\/its\/files\/2024\/11\/Pyramide_englisch_Blog.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"463\" src=\"https:\/\/blogs.ethz.ch\/its\/files\/2024\/11\/Pyramide_englisch_Blog-600x463.jpg\" alt=\"Improved resilience of data through categorisation in tiers\" class=\"wp-image-3629\" srcset=\"https:\/\/blogs.ethz.ch\/its\/files\/2024\/11\/Pyramide_englisch_Blog-600x463.jpg 600w, https:\/\/blogs.ethz.ch\/its\/files\/2024\/11\/Pyramide_englisch_Blog-300x231.jpg 300w, https:\/\/blogs.ethz.ch\/its\/files\/2024\/11\/Pyramide_englisch_Blog-1024x790.jpg 1024w, https:\/\/blogs.ethz.ch\/its\/files\/2024\/11\/Pyramide_englisch_Blog-768x592.jpg 768w, https:\/\/blogs.ethz.ch\/its\/files\/2024\/11\/Pyramide_englisch_Blog-1536x1184.jpg 1536w, https:\/\/blogs.ethz.ch\/its\/files\/2024\/11\/Pyramide_englisch_Blog-2048x1579.jpg 2048w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">In IT Services, we have developed a graduated data resilience strategy consisting of four data layers: Level 1 comprises the most critical and valuable data, whereas as level 4 at the bottom contains the least important data. All tiers are protected by geographically separate tape backups. In addition, Tiers 1, 2 and 3 have a special offline tape copy that is logically inaccessible, the so-called &#171;logical air gap&#187;. The data in Tiers 1 and 2 is also protected by a redundant storage system that can recognise ongoing malicious attacks in real time. Finally, Tier 1 data naturally receives the highest level of protection, including a physical air-gap system.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How do you correctly categorise data into the four available tiers?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This is the real challenge, because everyone thinks that their data deserves the best possible protection. There are obvious candidates for the upper tiers: all services that form the basis of the university infrastructure and on which all other systems and services depend, personnel and student data, as well as data that can never be recovered (such as seismic, historical data). For other types of data however, categorisation into tiers is much more difficult and requires input from senior management in collaboration and consultation with employees and researchers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you have any questions about the categorisation of data into the four tiers, please contact <a href=\"mailto:it_bcm@id.ethz.ch\" target=\"_blank\" rel=\"noreferrer noopener\">IT Service Continuity Management<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Contact<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Group, Storage, ITS INFRA, <a href=\"https:\/\/ethz.ch\/staffnet\/en\/organisation\/departments\/it-services.html\" target=\"_blank\" rel=\"noreferrer noopener\">IT Services<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>With malicious cyber attacks on the rise, every organisation needs to act and protect its data.<\/p>\n","protected":false},"author":838,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[257891,25],"tags":[301885,301882,301476,301884,301883,301886],"class_list":["post-3625","post","type-post","status-publish","format-standard","hentry","category-it-sec","category-news","tag-categorisation","tag-categorisation-to-protect","tag-eth-data","tag-protection","tag-tiered-data-protection","tag-tiers"],"_links":{"self":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/posts\/3625","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/users\/838"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/comments?post=3625"}],"version-history":[{"count":6,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/posts\/3625\/revisions"}],"predecessor-version":[{"id":3632,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/posts\/3625\/revisions\/3632"}],"wp:attachment":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/media?parent=3625"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/categories?post=3625"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/tags?post=3625"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}