A network-attached storage device, or NAS, is a standalone server with the ability to store files for users on a network.
ITS provides several sustainable and scalable digital storage solutions for WCM users. ITS storage solutions are centrally managed, meet security and privacy requirements permitting the storage of high risk data, and account for physical security, resiliency, and offsite backup. For additional information about ITS storage solutions, please visit the ITS website at http://its.weill.cornell.edu/services/storage-servers/file-sharing.
NAS devices managed individually and not stored within a WCM data center introduce added security risk. WCM is responsible for maintaining an asset inventory of WCM data. Departments who wish to use a NAS device must have the device “tagged” by ITS for asset tracking. The use and intent of the NAS device, including the type of data it will store, must be documented. Furthermore, the NAS device must meet the minimum security requirements in the section below.
NAS devices are not permitted to store protected health information as they do not offer offsite data backups to meet HIPAA requirements. ITS storage solutions must be used instead.
NAS devices must meet the following minimum security requirements:
ITS will regularly review NAS device configurations to ensure they continue to meet the above requirements.
ITS has reviewed various NAS devices. Many Synology and QNAP devices are capable of supporting the above security requirements (with added configuration). For some sample devices, please reference the models below:
Individuals wishing to utilize a NAS device should contact their ITS departmental liaison prior to purchase to ensure the device will meet the above security requirements. ITS Security will review and evaluate these requests.