1 Security Overview

This section gives an overview of Oracle's StorageTek SL150 Modular Tape Library and explains the general principles of tape library security.

Product Overview

StorageTek SL150 Modular Tape Library is a 19" rack mounted modular automated tape library by Oracle Corporation. It offers storage capacity for LTO tape cartridges, supports LTO Fibre Channel drives or SAS tape drives, and a bridged drive Fibre or SAS port control path through one of the installed tape drives. The SL150 v3.50 release has VPAT #6237 and #7171.

Security

All tape library products are designed and documented for use within a controlled server environment with no general network or user access. This provides the best functionality and protection from compromise, both from the internet in general and from the internal entity operating the library.

General Security Principles

The following principles are fundamental to using any product securely.

Keep Software Up To Date

One of the principles of good security practice is to keep all software versions and patches up to date. The SL150 Firmware versions released since June 2012 are as follows:


June 2012 v1.00 (RTA 0.1.0.0.0)
September 2012 v1.03 (RTA 0.1.0.3.0)
October 2012 v1.50 (RTA 0.1.5.0.0)
January 2013 v1.82 (RTA 0.1.8.2.0)
August 2013 v2.0 (RTA 0.2.0.0.0)
October 2013 v2.01(RTA 0.2.0.1.0)
April 2014 v2.25 (RTA 0.2.2.5.0)
June 2015 v2.50 (RTA 0.2.5.0.0)
March 2016 v2.60 (RA 0.2.6.0.0)
June 2017 v3.00 (RA 0.3.0.0.0)
November 2018 v3.20 (RA 0.3.2.0.0)
July 2018 v3.50 (RA 0.3.5.0.0)

Restrict Network Access

Keep the library behind a data center firewall. The firewall provides assurance that access to these systems is restricted to a known network route, which can be monitored and restricted, if necessary. As an alternative, a firewall router substitutes for multiple, independent firewalls. Identifying the hosts allowed to attach to the library and blocking all other hosts is recommended where possible.

Keep Up To Date on Latest Security Information

Oracle continually improves its software and documentation. Check this document every release for revisions.