Qumulo QaaS Enhanced Security Support for NFSv4.1 Protocol and Attestation of Compliance With SOC 2 Type II
And hired Kathy Ahuja as VP information security.
This is a Press Release edited by StorageNewsletter.com on July 28, 2022 at 2:01 pmQumulo, Inc. announced enhanced security support for network file system protocol NFSv4.1.
The company has also announced it has received an attestation of compliance with SOC 2 Type II, and has hired Kathy Ahuja as VP, information security.
The firm introduced Qumulo on Azure as a Service (QaaS) in July of 2021, so that multi-cloud organizations could store, manage, and curate their data with simplicity anywhere. To prove the security of its service across key criteria, the company engaged A-Lign, an independent auditing firm, to review its service data controls. This attestation of compliance with SOC 2 Type II for QaaS provides customers peace of mind that the data entrusted to QaaS will be secured.
With the enhancements to the NFSv4.1 protocol, there is additional support for authentication via Kerberos and file locking control. In NFSv3, users can impersonate any user with root access to their client machine. Kerberos solves this problem with cryptography techniques to securely authenticate users from a central identity provider, such as Microsoft Active Directory Domain Controllers or an open-source Kerberos Key Distribution Center (KDC).
The latest release includes improved lock handling for file access. When files are accessed by a client, they are locked to ensure that other clients cannot write data to the file, preventing potential corruption or version control issues. NFSv3 had known problems with orphaned sessions leaving files locked, requiring administrators to run a process to release locks from time to time. NFSv4.1 provides superior lock control and time outs to release locked files after some interval of inactivity.
Kathy Ahuja, VP information security
She joined the company as VP, information security to help customers and partners understand how the firm secures customer information, protects individual privacy, and complies with regulations and standards. Prior to the company, she built and ran security and compliance efforts at OneLogin, DocuSign, Microsoft, Oracle and Symantec.
“Qumulo’s security program is designed to achieve the most fundamental security requirements while giving customers the most control over their data. Qumulo is committed to protecting our customers’ data while providing transparency and trust,” she said.
In addition, the firm launched the Qumulo Trust Center. The Trust Center offers straightforward information about data privacy and security policies, practices, and operations at the company.
Resources:
Video: How Qumulo on Azure Makes Cloud File Services Simple
Blog: Qumulo Bolsters Data Security with NFSv4.1 Enhancements Including Kerberos-based Authentication and Improved File Locking