1. System upgrades should be promptly installed, but only after first testing them on an isolated non-production system.
2. Only install proven technologies in the SAN. Seek references for new technologies, as they would for new employees.
3. Collaboration with other organizations with similar SANs and configurations should be encouraged. Regular pooling of resources and experience of security problems is beneficial in raising SAN security.
4. Wherever possible, key servers in the SAN should be hardened which involves restricting the types of applications that can be installed, and the credentials that give access to the servers.
5. Security audits should be performed frequently, and system logs should routinely be scrutinized for unusual activity
6. Conduct an awareness program for key employees to keep them up to date with expected threats and countermeasures.
Source: SNIA SSIF Best Practices Document 2003:001