Tape Security and Storage¶
Security of tape copies within Cloud4You Tape as a Service is based on a combination of several mechanisms:
- physical separation of media from active infrastructure,
- controlled retention,
- media inventory in Veeam,
- the ability to encrypt data written to tape,
- protection of selected tapes against overwrite,
- periodic restore testing.
A typical model looks like this:
Cloud Repository
│
▼
Backup to Tape
│
▼
Write to physical media
│
▼
Eject / Export
│
▼
Tape offline
│
▼
Storage for the agreed period
Important
Detailed rules for physical storage, media location, and retention period are agreed according to the selected Tape as a Service option.
Why is tape an additional security layer?¶
Data stored on active backup systems remains online and accessible to Veeam infrastructure.
After writing, a tape can be:
and stored as:
media.
This means that after physical disconnection from the drive, it is no longer continuously accessible to production or backup systems.
Flow:
This model provides an additional protection layer against events affecting active infrastructure.
Air gap — what does it mean in practice?¶
With physical tape, true separation of media from IT infrastructure can be achieved.
After data is written:
Until the tape is loaded back into a library or drive, the Veeam infrastructure cannot write new data to it.
Note
Simply using tape does not automatically mean the medium is offline. A tape that remains in an active library is still available to the tape infrastructure. Therefore, media handling after job completion is an important part of the service.
Exporting tape after backup completion¶
Veeam allows automatic export of selected media sets after a job completes.
For GFS, this may include:
Example policy:
Weekly
├── remains in active rotation
└── retention 4 weeks
Monthly
├── export after writing
└── retention 12 months
Quarterly
├── export after writing
└── retention 24 months
Yearly
├── export after writing
└── retention 5 years
This allows short-term tapes to remain in operational use while long-term copies are taken offline.
Media Vault¶
Veeam Backup & Replication provides:
A Vault is a logical container used to track tapes located outside the library.
Veeam stores information in the Vault about:
- the medium,
- its previous library,
- Media Pool,
- data stored on tape,
- retention period.
Flow:
Info
Media Vault is a logical mechanism in Veeam. It is not a physical storage facility. It allows the system to reflect the actual location where offline media is stored.
Media inventory¶
Each tape used by Veeam is identified and registered in the Tape Catalog.
This makes it possible to determine, among other things:
When data needs to be restored, this helps identify the correct medium or set of media.
Example:
Encrypting data on tape¶
Veeam Backup & Replication supports encryption of data written to tape.
Two levels are available:
and:
Veeam can use hardware encryption provided by the tape library or drive, or software encryption performed by Veeam.
Info
If hardware encryption is available and enabled, Veeam gives it priority over software encryption.
Hardware encryption¶
In this model, encryption is performed by the tape device.
Flow:
Encryption is handled by the library or drive according to the capabilities of the specific hardware.
Warning
A hardware-encrypted tape may require compatible equipment and the correct encryption mechanism for later reading. This should be considered in the long-term retention plan.
Software encryption¶
If hardware encryption is not used, Veeam can encrypt data in software.
In this case, the data is encrypted by a Veeam component before being written to the medium.
Flow:
Encryption is configured at the:
level using:
Password or KMS¶
In Veeam Backup & Replication 13, tape encryption can use:
or:
A password is used to derive keys that protect the data.
Alternatively, an external KMS can be used to manage encryption keys.
Loss of key
Losing the password or losing access to the required KMS keys may make it impossible to restore data from an encrypted tape.
Encryption-key management must be part of the Disaster Recovery plan, not only part of backup configuration.
Double encryption¶
A scenario is possible in which the:
is already encrypted and the:
also uses tape encryption.
In this case, Veeam may store:
Flow:
Note
Double encryption increases requirements for correct password and key management. Restoring data later may require information for both the original backup encryption and the tape-encryption layer.
Protecting a tape from overwrite¶
In addition to standard retention, Veeam allows a selected tape to be marked as:
When enabled, Veeam applies:
protection to the medium.
Tape protection overrides Media Pool retention settings.
Veeam does not allow a protected tape to be:
- appended to,
- erased,
- marked as free,
- removed from the catalog.
Info
Protection can be applied to both online and offline tapes if they contain data.
Retention vs Protected¶
These are two different mechanisms.
Retention¶
Example:
After 12 months, the medium may be reused.
Protected¶
The tape remains protected regardless of Media Pool retention until an administrator deliberately removes protection.
Flow:
WORM¶
For environments requiring durable protection against rewriting, compatible:
media can be used.
Once data is written, such media cannot be reused in the same way as standard rewritable tape.
Veeam supports:
Note
Availability of WORM in Cloud4You Tape as a Service depends on the infrastructure in use and the purchased service scope. A WORM requirement must be declared before archiving starts.
GFS retention¶
Standard tape-data protection can be implemented using a GFS policy.
Example:
While retention is active, data is protected from reuse of the medium according to the policy of the specific Media Set.
More information:
Offline storage¶
A medium intended for offline storage should, after the required operations are complete, be:
1. correctly finalized in Veeam
2. exported / removed from the library
3. registered as offline media
4. assigned to the correct location / Vault
5. stored for the required period
Example:
Physical media storage¶
Tapes are physical data media and require appropriate handling.
For long-term storage, take into account:
- conditions recommended by the media manufacturer,
- protection against mechanical damage,
- protection against unauthorized access,
- media traceability,
- retention-period control,
- the ability to locate a specific tape during restore.
Important
Exact physical storage conditions depend on the tape generation and manufacturer. Follow the media manufacturer's requirements instead of assuming one universal temperature or humidity value for all tapes.
Physical location vs Media Vault¶
For each tape placed into storage, it is worth maintaining consistency between:
Example:
This makes it possible to quickly determine where the required medium is located during restore.
Media transport¶
If tape is moved between locations, the process should ensure:
- media identification,
- controlled handover and receipt,
- preservation of location information,
- protection against damage,
- access restricted to authorized personnel.
After a location change, update the logical media inventory in Veeam as well if it is used to represent the physical storage location.
Data removal after retention expires¶
After the agreed retention period ends, the medium may be:
or handled according to individual arrangements.
For standard tape, Veeam may reuse the medium after the protection period expires.
If the data must not be rewritten or the medium requires durable protection, consider:
or:
according to service requirements.
Encryption-key security¶
For encrypted tapes, data security also depends on availability of the correct keys.
Good practices include:
- storing the password outside the backup server,
- controlling access to passwords and KMS,
- having a key-recovery procedure,
- documenting responsibility for key management,
- testing restores from encrypted tapes.
Danger
Possessing the physical tape without being able to decrypt its contents does not constitute a usable backup copy.
Restore testing¶
Backup security does not end when the tape is written.
Periodically perform:
For important systems, extend the test to:
More information:
Example security policy¶
An example model can look like this:
Weekly
├── retention 4 weeks
└── active rotation
Monthly
├── retention 12 months
├── encryption
└── export after writing
Quarterly
├── retention 24 months
├── encryption
├── export after writing
└── offline storage
Yearly
├── retention 5 years
├── encryption
├── export after writing
├── offline storage
└── optionally Protected / WORM
Note
This is an example architecture, not the default configuration of every Cloud4You service. The required protection scope should be defined when ordering Tape as a Service.
Data-protection layers¶
Tape as a Service can be treated as another layer in a backup strategy:
LAYER 1
Production
↓
LAYER 2
Local backup
↓
LAYER 3
Cloud4You Cloud Repository
↓
LAYER 4
Tape
↓
LAYER 5
Tape offline / long-term retention
As a result, failure of one layer does not necessarily mean loss of all copies.
What should be agreed before ordering?¶
For security-related requirements, define:
[ ] whether tapes should be encrypted
[ ] whether WORM is required
[ ] which media sets should be exported
[ ] how long they should remain offline
[ ] whether Never overwrite protection is required
[ ] how often restore testing will be performed
[ ] the required RTO for tape data
RTO and offline storage¶
Offline tape provides stronger separation from active infrastructure, but it may also increase restore time.
The process may require:
locating the medium
↓
preparing the tape
↓
loading it into the library
↓
Inventory / Catalog
↓
reading the data
↓
restore to repository
↓
final restore
Therefore, service design should balance:
against:
Summary¶
The most important Tape as a Service security mechanisms are:
| Mechanism | Purpose |
|---|---|
| Export / Eject | physically disconnect the medium |
| Offline storage | separation from active infrastructure |
| Media Vault | inventory of tapes outside the library |
| GFS Retention | protection against premature overwrite |
| Tape Encryption | data confidentiality |
| Protected | Never overwrite for a specific tape |
| WORM | durable restriction of rewriting |
| Restore tests | verification of actual recoverability |
A well-designed policy can combine several mechanisms:
Related guides¶
- About Tape as a Service
- One-time Backup
- Recurring Backup
- GFS Retention
- Available Retention Options
- Restoring Data from Tape
- Ordering the Service