Skip to content
Data Protection, Security and Compliance

How to build a Zero Trust Recovery Solution with Commvault and Metallic

Why Zero Trust is important, what it is and how to harden your infrastructure by adopting Zero Trust principles using Commvault and Metallic. 


President Biden’s cybersecurity executive order is clear as day … Zero Trust Architecture and modernized infrastructure is the key to protecting the nation’s data against the rampant threat landscape. We’ve seen the devastating effects firsthand with a ransomware attack disrupting gasoline distribution, causing outages and increased prices across the United States. It’s a global problem and statistically growing month on month from last year. https://www.blackfog.com/the-state-of-ransomware-in-2021/

In this blog post, I’ll explain why Zero Trust is important, what it is and how to harden your infrastructure by adopting Zero Trust principles using Commvault and Metallic. 

What is Zero Trust? 

Zero Trust is not a singular technology or feature. Zero Trust is a collection of design principles for IT infrastructure that enforces a “trust no one; always validate trust” approach to data access.  

A great way to visualize Zero Trust Architecture is to think of home security. Around the perimeter of your house, you have cameras, locks, window sensors, and a fence. Essentially all your belongings are safe inside the perimeter of the house. However, if you have friends and acquaintances over for coffee, you have authorized entry into your home – at that point, your personal belongings are accessible and at risk of theft.  

The above example perfectly illustrates a traditional approach to security – wherein firewalls provide perimeter security (keep the bad guys out) and user permissions control access. Once a bad actor gets in and gains access to privileged credentials (which they do) – they often go unchallenged while laterally moving through the environment doing damage.  

Con un enfoque de «Zero Trust», el acceso privilegiado se somete a continuas comprobaciones, lo que limita la capacidad de los actores maliciosos para moverse y actuar con eficacia. Volviendo al ejemplo de la casa, el hecho de que esté autorizado a entrar en ella no significa que pueda hacerlo sin más: las cajas fuertes con combinación, las cerraduras de las puertas interiores y las cámaras internas proporcionan múltiples capas de control y validación. Por lo tanto, aunque esté autorizado a entrar en la casa, debo seguir identificándome introduciendo la combinación de la caja fuerte o utilizando las llaves de las puertas de los dormitorios si intento moverme por la casa.

Key principles of Zero Trust

National Institute of Standards and Technology (NIST) SP 800-207 is the definitive reference guide for Zero Trust Architecture (ZTA). Many of the principles outlined within the NIST publication have been implemented as features and best practices allowing the Commvault platform to be fully deployed in a Zero Trust architecture. Additionally, Metallic™ Data Management as a Service (DMaaS) is completely architected in the cloud using Zero Trust principles from the ground up. A few key principles outlined by NIST are Least privilege access, multi-factor authentication, and Micro-segmentation. Let’s explore this further.

Least privilege access – NIST SP 800-207 Section 2.1

The concept of least privilege access provides users and/or accounts with the bare minimum capabilities to do their job and nothing more. This minimizes exposure if the account is compromised, as well as limits data access leaks. Commvault  can lock down backup data using role based access controls and special data privacy locks. It is easy to limit users to specialized capabilities such as restore only or view only. You can additionally restrict browse/restore access to data owners, only superseding any global level admin capabilities. Additional integration with Privilege Access Management (PAM) platforms like CyberArk® further improves security posture through policy-driven account management, credential rotation, and privilege session management.

Multi-Factor Authentication – NIST SP 800-207 Section 2.1

Multi-Factor Authentication (MFA) is another key Zero Trust concept. Since trust needs to be continuously validated – MFA provides an additional layer of validation for any authentication request making it difficult for a threat actor to gain access to data. Commvault and Metallic BaaS supports modern implementations of MFA through its SAML-based authentication framework. Using Azure AD, ADFS, Okta, or other IDP, Commvault allows customers to deploy pin-based MFA tools and hardware authentication tools to control data access to backups.

Las implementaciones locales que utilizan cuentas de Active Directory (AD) o cuentas locales cuentan con autenticación de dos factores (2FA) integrada, lo que permite a las organizaciones utilizar cualquier aplicación generadora de códigos PIN basada en el algoritmo de contraseña de un solo uso basada en el tiempo (TOTP) especificado en el RFC 6238, como Google Authenticator, Microsoft Authentication y muchas otras.

According to the NIST Digital Identity guidelines (NIST 800-63) cross referenced in their ZTA publication; hardware authentication technologies offers one of the highest standards for MFA providing Authenticator Assurance Level 3.  This includes MFA technologies using modern specifications such as FIDO/FIDO2.  Commvault is fully integrated with FIDO/FIDO2 MFA devices, such as offered through Yubico’s YubiKey as well as PKI based Common Access Cards.  This completely maximizes the level of protection from illegitimate authentication attempts and future proofs your data protection environment.

Una vez iniciada sesión en la interfaz de gestión, el marco de autorización de comandos valida las acciones realizadas en dicha interfaz. Independientemente del rol del usuario, cualquier solicitud de eliminación, restauración o configuración requiere la autorización de una autoridad competente. Esto protege contra las amenazas internas, tanto maliciosas como accidentales, y mantiene los datos a salvo de acciones destructivas.

Micro-segmentation – NIST SP 800-207 Section 3.1.2

La microsegmentación es otro principio clave del modelo «Zero Trust». La microsegmentación es la técnica que consiste en separar los recursos tanto a nivel lógico como físico para que el acceso sea muy restrictivo y controlado.

Las instalaciones locales pueden utilizar técnicas de segmentación de red para aislar y crear un «air gap» (aislamiento físico) entre los destinos de almacenamiento y el resto de la red. Una vez segmentada la arquitectura de red, se deben aplicar las topologías de red de Commvault para bloquear las conexiones entrantes al destino de almacenamiento y automatizar las políticas de acceso mediante listas blancas, permitiendo únicamente las conexiones de autenticación salientes para extraer datos y trasladarlos al almacén de datos seguro. Muchos de nuestros clientes también optan por segmentar los datos en la nube, aprovechando los controles de almacenamiento WORM que ofrece el proveedor de servicios en la nube.

Metallic Cloud Storage Service (MCSS) provides an even simpler air gap approach requiring no infrastructure change.  MCSS is a cloud storage target managed through Metallic, offering offsite, secure air gapped data protection capabilities for the Commvault platform. Data protected in MCSS is unchangeable and cannot be accessed or exposed on the backend cloud account.  The data is protected in Metallic’s zero trust architected environment. This provides an easy method to segment and separate data from an on-premises environment. 

In addition to physical segmentation, data management can also be logically segmented. Using multi-tenancy controls; access to data is segmented and compartmentalized, reducing potential data exposure. 

Encryption key management can also be segmented across several KMS systems such as AWS Key Management Service, Azure KeyVault, as well as with one of many certified KMIP providers  providing greater levels of protection against data access.

Metallic DMaaS Architecture

For a fully zero trust managed platform, look no further than Metallic.  Metallic is a multi-tenant SaaS Platform with built in-segregation between tenants. Customer data is wholly isolated and stored in separate locations, creating a virtual air-gap between source environments and backup data copies. Hardened security and zero-trust access controls, including multifactor authentication, role based access, advanced data encryption, and privacy locks, prohibit unauthorized access to and lateral movement of data. Metallic also meets the industry’s most stringent security standards and maintains HIPAA, ISO27001, GDPR, and SOC 2 compliance, as well as the only SaaS data protection to achieve FedRAMP High In Process – In PMO Review standard.

Conclusion

Como puedes ver, tanto si implementas una solución de Commvault en tus propias instalaciones, como si utilizas Metallic DMaaS o cualquier combinación de todas estas opciones, la plataforma de Commvault está protegida mediante los principios de la arquitectura «Zero Trust».

Learn more by attending the upcoming Commvault webinar “«Beyond Trust” on March 23rd.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements