This IBM Redbooks® publication provides comprehensive guidance on installing, configuring, and utilizing IBM Fibre Channel Endpoint Security (IFCES). The primary focus of this publication centers on securing critical Fibre Channel connections between IBM Z host servers and IBM DS8000 storage systems that support the IFCES framework.
IFCES establishes a trusted storage network by delivering two distinct layers of Fibre Channel link protection: link authentication and data-in-flight encryption. Enabling link encryption automatically enforces link authentication protocols.
This end-to-end security solution is explicitly engineered for enterprises that must strictly comply with the Payment Card Industry Data Security Standard (PCI DSS) and other stringent regulatory frameworks. as well as organizations seeking to eliminate the risk of unauthorized access or data interception across the storage area network.
This publication is intended for IBM Z and IBM Storage architects, storage administrators, security specialists, systems programmers, implementation consultants, and support professionals who design, deploy, secure, and manage DS8000 storage environments using IFCES.
Chapter 1. Introducing IBM Fibre Channel Endpoint Security
Chapter 2. IBM Fibre Channel Endpoint Security solution design
Chapter 3. Endpoint Security requirements and planning
Chapter 4. Implementation
Chapter 5. Monitoring and maintaining the Endpoint Security environment
Chapter 6. Managing certificates
The material included in this document is in DRAFT form and is provided 'as is' without warranty of any kind. IBM is not responsible for the accuracy or completeness of the material, and may update the document at any time. The final, published document may not include any, or all, of the material included herein. Client assumes all risks associated with Client's use of this document.