Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.
Version: 2.15.0

Compliance Guide for AirGap for Dell

Introduction

This page summarizes the compliance posture of AirGap at a solution level: how data is kept immutable, how AirGap operations are audited, and how role-based access control is applied. For the detailed NIST framework mapping specific to AirGap for ECS, see NIST Compliance Mapping below.

Data Immutability

The vault copy of your data is protected using SyncIQ, which locks replicated data in a read-only state on the vault PowerScale cluster.

  • Replicated data cannot be deleted or modified, even by the root user on the vault cluster.
  • Immutability applies regardless of the permissions applied to the data.
  • Replication can be scoped to the entire source cluster or to specific paths, by creating additional SyncIQ policies for the paths that require protection.
info

This immutability guarantee comes from SyncIQ's target-cluster locking behavior, not from AirGap network isolation alone. Network isolation (the "air gap") protects the vault cluster from being reached at all outside of scheduled or maintenance windows; SyncIQ target locking protects the data itself even during those windows.

Audited Operations

AirGap includes several built-in checks that generate alarms for compliance and operational auditing purposes, covering network-state tampering detection, missed scheduled jobs, daily replication reporting, and policy-configuration change auditing. The full list of these built-in checks is documented once, in detail, in References, to avoid maintaining the same list in two places.

Role-Based Access Control

AirGap supports discrete, separately assignable roles so that AirGap administration can be kept independent of day-to-day Ransomware Defender monitoring:

  • Ransomware Defender Role – day-to-day configuration/management of real-time monitoring (recommended for the infosec team).
  • Easy Auditor Role – day-to-day auditing configuration (recommended for the infosec team).
  • AirGap Role – access to AirGap configuration (recommended for CSO or senior management, kept separate from the Ransomware Defender role holders).
  • Read-only variants of the Ransomware Defender and Easy Auditor roles are also available, so the NAS team can have visibility without the ability to make changes.

Vault Cluster Hardening Baseline

The following hardening practices apply to the vault PowerScale cluster and support a stronger compliance posture:

  • Use only local accounts on the vault cluster; do not join it to an AD provider.
  • Enable configuration auditing on the vault cluster to track all configuration changes.
  • Disable non-essential services (SMB, NFS) and delete default SMB shares and NFS exports.
  • Disable all built-in user accounts except root. The root password should be a random, 20+ character password with a mix of upper case, lower case, numbers, and special characters, created and managed only by senior security management.
  • Create a dedicated Eyeglass service account with minimum permissions for vault alarm collection, rather than using an administrative account.
note

A full hardening pass beyond the baseline above is available through Superna's AirGap Design and Implementation professional service, together with Dell PowerScale hardening documentation.

NIST Compliance Mapping

A detailed NIST Framework compliance mapping table for AirGap running on Dell ECS is documented on the AirGap for ECS configuration page and is not duplicated here.

See Also

  • AirGap for ECS – NIST Key Framework Attribute compliance table.
  • Disclaimers – Legal and functional-specification notices related to this solution.