Skip to content
Clumio

Amazon S3 Data Protection using Protection Groups


As highlighted in one of the recent posts for Clumio Protect for Amazon S3, customers face several challenges in order to successfully differentiate between critical and non-critical data and be able to only protect critical data. This data classification challenge is solved by Clumio using an innovative concept called Protection Groups. I’ll dive deeper into how Protection Groups can be used to not just help classify critical data, but also protect it while producing tremendous cost savings.

Protection Groups ofrece una capa de abstracción para gestionar los buckets y los prefijos en todas tus cuentas de AWS. Proporciona un mecanismo para clasificar los datos en los distintos buckets de todas tus cuentas de AWS, con el fin de ayudar a proteger los datos críticos según los requisitos de la empresa.

La configuración de los grupos de protección es un proceso sencillo de tres pasos

Paso 1: Una vez que le hayas asignado un nombre intuitivo, podrás decidir qué buckets añadir a los grupos de protección. Estos buckets pueden pertenecer a una cuenta específica de AWS o estar repartidos entre todas tus cuentas de AWS. En un futuro próximo, también podrás añadir buckets mediante etiquetas, de modo que se incorporen automáticamente a los grupos de protección.

Paso 2: Decide si se añade todo el depósito o solo una parte del mismo al grupo de protección. Puedes utilizar tres criterios diferentes para seleccionar qué datos se van a proteger. Estos son:

  • Prefix: You can configure to include specific prefixes or exclude them depending on what you want to protect. For example; several customers dump their DB logs into a specific prefix and want that data to be protected. They can configure /dblogs/ to protect all objects sitting inside that prefix to be protected. If needed, they can even exclude a prefix to not get protected.
  • Storage Class: You can configure what objects to backup depending on their Storage Class. For example; you can configure to backup objects sitting in Standard and Infrequent Access only while not protecting objects in Glacier. This will reduce the time and cost significantly as objects stored in colder storage require time to unthaw and are expensive to pull out.
  • Version: You can configure whether to protect all versions or just the latest versions of the objects.

Paso 3: Aplicar una política al grupo de protección para que los datos puedan protegerse de acuerdo con los requisitos de la empresa.

And voila!! That’s it!! Your Amazon S3 data is protected in an air gap environment giving you protection against events like Ransomware or bad actors deleting/modifying your AWS environment.

Several customers have requirements to represent the state of their bucket at a specific point in time. They assumed that S3 Object Versioning is able to achieve the same thing, but it’s really not. We’ve created a simple table below to highlight the differences between the two:

Scope AWS S3 Versioning Clumio Protection Group
Protection Granularity Solo depósitos Una a varias cuentas
Una a varios buckets
Una a varios prefijos
Recovery Points Cambios en los objetos Momento
concreto Diario, mensual, anual
Recovery Granularity Solo objetos Una a varios buckets
Una a varios prefijos
«uno a muchos» Objetos «uno a muchos»
Recovery Location Solo cuenta local Cualquier depósito en cualquier cuenta
de AWS Restauración a cualquier prefijo, ya sea existente o nuevo

Como puedes ver, Clumio ayuda a los clientes a… y también facilita su restauración.

However, any backup is only as good as its recovery and customers require flexibility to recover a specific object, or an entire prefix, or entire bucket, and even multiple buckets at the same time. With protection groups, Clumio enables you to do all of these our unique capability to perform Global Search across all of your critical data sitting in different AWS accounts. Keep an eye out for a future blog where I dive into Amazon S3 data recovery coupled with Global Search and show how Clumio can help you recover your data.

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements