Compliance Guide for AirGap for Dell
Introduction
This page summarizes the compliance posture of AirGap at a solution level: how data is kept immutable, how AirGap operations are audited, and how role-based access control is applied. For the detailed NIST framework mapping specific to AirGap for ECS, see NIST Compliance Mapping below.
Data Immutability
The vault copy of your data is protected using SyncIQ, which locks replicated data in a read-only state on the vault PowerScale cluster.
- Replicated data cannot be deleted or modified, even by the root user on the vault cluster.
- Immutability applies regardless of the permissions applied to the data.
- Replication can be scoped to the entire source cluster or to specific paths, by creating additional SyncIQ policies for the paths that require protection.
This immutability guarantee comes from SyncIQ's target-cluster locking behavior, not from AirGap network isolation alone. Network isolation (the "air gap") protects the vault cluster from being reached at all outside of scheduled or maintenance windows; SyncIQ target locking protects the data itself even during those windows.
Audited Operations
AirGap includes several built-in checks that generate alarms for compliance and operational auditing purposes, covering network-state tampering detection, missed scheduled jobs, daily replication reporting, and policy-configuration change auditing. The full list of these built-in checks is documented once, in detail, in References, to avoid maintaining the same list in two places.
Role-Based Access Control
AirGap supports discrete, separately assignable roles so that AirGap administration can be kept independent of day-to-day Ransomware Defender monitoring:
- Ransomware Defender Role – day-to-day configuration/management of real-time monitoring (recommended for the infosec team).
- Easy Auditor Role – day-to-day auditing configuration (recommended for the infosec team).
- AirGap Role – access to AirGap configuration (recommended for CSO or senior management, kept separate from the Ransomware Defender role holders).
- Read-only variants of the Ransomware Defender and Easy Auditor roles are also available, so the NAS team can have visibility without the ability to make changes.
Vault Cluster Hardening Baseline
The following hardening practices apply to the vault PowerScale cluster and support a stronger compliance posture:
- Use only local accounts on the vault cluster; do not join it to an AD provider.
- Enable configuration auditing on the vault cluster to track all configuration changes.
- Disable non-essential services (SMB, NFS) and delete default SMB shares and NFS exports.
- Disable all built-in user accounts except root. The root password should be a random, 20+ character password with a mix of upper case, lower case, numbers, and special characters, created and managed only by senior security management.
- Create a dedicated Eyeglass service account with minimum permissions for vault alarm collection, rather than using an administrative account.
A full hardening pass beyond the baseline above is available through Superna's AirGap Design and Implementation professional service, together with Dell PowerScale hardening documentation.
NIST Compliance Mapping
A detailed NIST Framework compliance mapping table for AirGap running on Dell ECS is documented on the AirGap for ECS configuration page and is not duplicated here.
See Also
- AirGap for ECS – NIST Key Framework Attribute compliance table.
- Disclaimers – Legal and functional-specification notices related to this solution.