14
© 2015 by The Enterprise Strategy Group, Inc. All Rights Reserved. The Challenges The ability to share files using consumer-oriented, public-cloud services has become mainstream. The problem with these public cloud solutions is that they were designed for synchronizing pictures, music, and personal documents, not business data—so data security was not an essential part of the design spec. When employees use these services for storing and sharing business data, it exposes the sensitive (and sometimes regulated) data that businesses depend on to the risks of data loss, leakage, and even malware attacks. ESG research indicates that for both current and potential users of any type of online file sharing (OFS), security was by far the top most-cited concern. 1 Other key challenges included employees continuing to use their own solutions and integration with current IT tools and applications. Figure 1. Online File Sharing Challenges: Current and Potential Users Source: Enterprise Strategy Group, 2015. 1 Source: ESG Research Report, Online File Sharing and Collaboration: Deployment Model Trends, February 2014. 19% 30% 30% 17% 27% 50% 23% 24% 24% 24% 26% 40% 0% 10% 20% 30% 40% 50% 60% Migrating data into the service Integration with our existing IT tools and applications Employees continuing to use their own solutions File size limitations restrict our use cases Training users on new tools and processes Security concerns Challenges current users have experienced with and concerns potential adopters have about corporate OFS accounts. (Percent of respondents, multiple responses accepted) Current OFS users Potential OFS Users ESG Lab Review Secure, Scalable File Sync and Share: Citrix ShareFile Enterprise on EMC Isilon Storage Date: September 2015 Author: Kerry Dolan, Lab Analyst Abstract: This ESG Lab Review documents hands-on testing of a joint solution for enterprise file sync and sharing that combines Citrix ShareFile with EMC Isilon scale-out storage. These two products provide a “better together” solution for organizations looking for secure, highly scalable enterprise file sync and sharing (EFSS) that meets employee feature/function needs while delivering simplified IT management, higher security, and non-disruptive scalability.

ESG Lab Review: Citrix ShareFile on EMC Isilon Storage · Migrating data into the service Integration with our ... This ESG Lab Review documents hands-on testing of a joint ... web

Embed Size (px)

Citation preview

© 2015 by The Enterprise Strategy Group, Inc. All Rights Reserved.

The Challenges

The ability to share files using consumer-oriented, public-cloud services has become mainstream. The problem with these public cloud solutions is that they were designed for synchronizing pictures, music, and personal documents, not business data—so data security was not an essential part of the design spec. When employees use these services for storing and sharing business data, it exposes the sensitive (and sometimes regulated) data that businesses depend on to the risks of data loss, leakage, and even malware attacks. ESG research indicates that for both current and potential users of any type of online file sharing (OFS), security was by far the top most-cited concern.1 Other key challenges included employees continuing to use their own solutions and integration with current IT tools and applications.

Figure 1. Online File Sharing Challenges: Current and Potential Users

Source: Enterprise Strategy Group, 2015.

1 Source: ESG Research Report, Online File Sharing and Collaboration: Deployment Model Trends, February 2014.

19%

30%

30%

17%

27%

50%

23%

24%

24%

24%

26%

40%

0% 10% 20% 30% 40% 50% 60%

Migrating data into the service

Integration with our existing IT tools andapplications

Employees continuing to use their ownsolutions

File size limitations restrict our use cases

Training users on new tools andprocesses

Security concerns

Challenges current users have experienced with and concerns potential adopters have about corporate OFS accounts. (Percent of respondents, multiple responses accepted)

CurrentOFSusers

PotentialOFSUsers

ESG Lab Review

Secure, Scalable File Sync and Share: Citrix ShareFile Enterprise on EMC Isilon Storage

Date: September 2015 Author: Kerry Dolan, Lab Analyst

Abstract: This ESG Lab Review documents hands-on testing of a joint solution for enterprise file sync and sharing that combines Citrix ShareFile with EMC Isilon scale-out storage. These two products provide a “better together” solution for organizations looking for secure, highly scalable enterprise file sync and sharing (EFSS) that meets employee feature/function needs while delivering simplified IT management, higher security, and non-disruptive scalability.

ESG Lab Review: Secure, Scalable File Sharing Solution: Citrix ShareFile on EMC Isilon 2

© 2015 by The Enterprise Strategy Group, Inc. All Rights Reserved.

Consumer solutions provide the functionality and ease of use that users want—and are now quite familiar with—but without the security and protection that businesses require. And as long as typical business files are stored only in NAS arrays and document repositories, with restricted access and lack of “share-ability,” end-users will continue to use public, unprotected solutions.

Another challenge is the huge growth in file data that continues to strain NAS systems. Managing data growth is perennially among the top three most-cited IT priorities, according to ESG research,2 making it essential that enterprise file sync and sharing solutions scale easily. Also, large files such as video, images, and x-rays, etc. are increasingly cumbersome to access via technologies like FTP. Access to large files can be difficult unless the user is collocated with the infrastructure storing these files. In addition, users want mobile access to data in network shares, SharePoint, OneDrive for Business, ECM systems, and other repositories from any device and from any location; with traditional file sync and sharing solutions, data in these repositories must be physically moved into a different infrastructure silo to be available for mobile access and synchronization.

“Better Together” Solution: Citrix ShareFile Enterprise on EMC Isilon

Two industry leaders have teamed up to offer a joint solution for enterprise file sync and sharing (EFSS) requirements that stores data on-premises, and is simple to manage and deploy, resilient, and easy to scale. Citrix ShareFile Enterprise on EMC Isilon’s private cloud deployment enables secure, on-premises access to data from anywhere, on any device, delivering both the features that users demand, and the security, scalability, and management that IT needs. File data remains behind the corporate firewall with locally controlled encryption keys, IT accountability, and latency-free access. The result is an EFSS solution that reduces risk, improves performance, and ensures regulatory compliance.

Citrix ShareFile

Citrix ShareFile is a secure data sync and sharing application with flexible storage options that enable IT to mobilize enterprise file data. ShareFile enables mobile productivity with read-write access to data, workflows, and collaboration, allows users to securely share files with anyone, and enables file syncing across multiple devices. The ShareFile Control Plane is hosted in a secure, SSAE-16-certified Citrix data center and managed as a service, performing tasks such as user authentication, access control, reporting, and brokering. No customer data traverses the control plane.

ShareFile StorageZones functionality provides options for where data is stored (in the cloud, on-premises, or in a hybrid deployment), offering optimal performance by enabling IT to store data in close proximity to the user. This joint solution with EMC Isilon is designed for the added security of customer-managed, on-premises StorageZones that support any CIFS-based network share. Data is encrypted at rest using customer-managed encryption keys.

A key part of the customer-managed StorageZone is the StorageZone Controller, a physical or virtual Windows-based web service that handles all HTTPS operations from users and the control plane and enables mobile device access. StorageZone Connectors built into ShareFile web, desktop, and mobile clients enable organizations to mobilize data in network drives, Microsoft SharePoint sites, and enterprise content management systems as well as ShareFile data. These connectors enable secure access to the on-premises repositories behind your firewall, providing the ability to download files to a mobile device, view, edit, and save back to the original location (including SharePoint check-in/check-out).

ShareFile desktop integration with the native Windows Explorer and Macintosh Finder ensure a familiar experience for the user. Data in the ShareFile client My Files and Folders folder can be synced automatically or on-demand. Integration with Active Directory and support for SAML 2.0 provide seamless authentication to ensure corporate security and simplify user provisioning.

Other enterprise features include:

Robust security. ShareFile capabilities that can be configured based on data sensitivity include data encryption, selective remote wipe, device locking, passcode protection, whitelisting/blacklisting for apps and

2 Source: ESG Research Report, 2015 IT Spending Intentions Survey, February 2015.

ESG Lab Review: Secure, Scalable File Sharing Solution: Citrix ShareFile on EMC Isilon 3

© 2015 by The Enterprise Strategy Group, Inc. All Rights Reserved.

web sites, access control configuration, and data expiration policies. IT reporting and auditing on files, folders, and users help to maintain compliance and corporate governance policies.

Microsoft Outlook plug-in. This enables users to convert attachments into links to simplify sharing of large files without clogging up the network. Employees can download the plug-in themselves and easily customize the settings. For example, by configuring e-mails to use ShareFile links for files above a certain size threshold, organizations can offload those tasks from Exchange servers and still enable large file access. The Outlook plug-in also provides data tracking ability with the option to require login to access these files.

Mobile client in-app editing. On the mobile client, a built-in document creation and editing capability allows users to create, edit, and save Microsoft Office documents and annotate PDF files, while restricting third-party editors that create unsecured file copies.

EMC Isilon EFSS Storage Solution

One essential component of a successful private cloud EFSS solution is a storage infrastructure that scales quickly, easily, and non-disruptively. File data volumes residing in corporate data stores are growing exponentially with no sign of let up, and users need access via any device from any location. The additional devices and more frequent access place a greater burden on the storage infrastructure. This has a direct impact on the user experience: if adding capacity and provisioning users for your corporate EFSS solution are intrusive and time-consuming, users will avoid using it. It is simply too easy for them to whip out a credit card and grab capacity from a public cloud provider—negating the privacy, security, and control benefits of the private cloud.

EMC Isilon storage was designed to ensure simplicity, performance, flexibility, and scalability while ensuring data protection and security for unstructured file data. These features make EMC Isilon a beneficial foundation for EFSS solutions. Isilon is a modular, scale-out NAS system, so when you add nodes you increase both capacity and throughput, ensuring that bandwidth doesn't create a bottleneck; performance scales with capacity. Also, just-in-time scalability and simple provisioning ensure that capacity comes online quickly. Isilon scales to 50PB in a single namespace, consolidated in a smaller footprint with high utilization. This enables IT to consolidate storage for EFSS and other applications and business processes, eliminating silos of storage to manage. Isilon automatically load balances and tunes as nodes are added, so you can keep up with data growth without increasing administrative effort or having to migrate data to another platform. Administrative burden does not increase as you grow. The EMC Isilon OneFS operating system enables:

Scalability to 50PB and 3.75 million file operations per second with 200+ GB/s aggregate throughput in a single file system.

Security, including file system auditing, data-at-rest encryption, and self-encrypting drives.

Operational flexibility with multi-protocol support including NFS, SMB, HTTP, FTP, and native HDFS support.

EMC Isilon SmartLock to protect against accidental, premature, or malicious alteration or deletion.

Enterprise data protection with N+1 through N+4 redundancy.

EMC Isilon SmartDedupe for storage efficiency. Data deduplication enables data to be contained with less physical storage, saving on capital and operational costs.

EMC Isilon AutoBalance automatically load balances data as you scale, ensuring that you can quickly and easily add Isilon nodes without downtime and without manually moving data or reconfiguring applications.

EMC Isilon SmartPools automated tiering, including an option for up to 700TB of flash cache in a cluster.

EMC Isilon SnapShotIQ for data-efficient, low-overhead snapshots and fast restore.

EMC Isilon SyncIQ data replication for disaster recovery and failback.

Additional tools for performance, resource, and access management.

Together, Citrix ShareFile and EMC Isilon deliver the features that users need on a safe, secure, scalable platform.

Figure 2 provides a logical overview of a ShareFile on Isilon deployment. The left side shows users access modes, including desktop/laptop, Web browser, and mobile devices. Users log into the cloud-based ShareFile Control Plane, hosted in Citrix data centers in the U.S. or Europe, which manages (as a service) authentication and access control as

ESG Lab Review: Secure, Scalable File Sharing Solution: Citrix ShareFile on EMC Isilon 4

© 2015 by The Enterprise Strategy Group, Inc. All Rights Reserved.

well as system and user reporting. Access from any device or browser connects using 256-bit SSL encryption. Requests are distributed to firewall-protected servers via NetScaler load balancing. Web and application servers handle portal access. A clustered, replication-protected database stores only user account information and access rights for files and folders based on metadata—no customer data is stored in the control plane.

Figure 2. Citrix ShareFile and EMC Isilon Deployment

The customer-managed StorageZone keeps file data on-premises within the Isilon private cloud. ShareFile supports any CIFS network share, making it simple to integrate into the Isilon infrastructure. The StorageZone Controller Windows-based web service handles all HTTPS operations from users and the control subsystem, as well as enabling StorageZone Connectors.

ESG Lab Tested

ESG Lab tested both user and administrative features of the ShareFile on Isilon deployment. Also included were Isilon features that are key for a successful EFSS deployment, including deduplication, non-disruptive scalability, and automatic load balancing.

For this testing, the customer-managed StorageZone was located at Superna labs in Toronto, Ontario, Canada. It was stored in a three-node Isilon NL400 cluster with a 10 GbE network; the StorageZone Controller was a Windows 2012 virtual machine. The control plane was housed in the ShareFile Europe cloud.

Administrative Testing

ESG Lab began by exploring the management console and executing common tasks such as adding accounts, configuring permissions and settings, browsing groups, and running reports. ShareFile has a wide range of tasks that enterprises can manage. Employee accounts can be added via Active Directory, using a spreadsheet, or manually. Client accounts with

ESG Lab Review: Secure, Scalable File Sharing Solution: Citrix ShareFile on EMC Isilon 5

© 2015 by The Enterprise Strategy Group, Inc. All Rights Reserved.

fewer features and permissions can be created for users outside of the domain, such as contractors, enabling collaboration and sharing to the extent desired. Administrators can track and report on both employee and client activities. They can also get reports on file, folder, and repository activities including users, uploads/downloads/creates/deletes, bandwidth and storage usage, and more. Other enterprise features include single sign-on/SAML and custom branding.

Adding employees requires input of basic information (including bandwidth limitation if desired), selection of a default StorageZone, and configuration of file, folder, and device permissions, including shared folders. Figure 3 shows the primary Create New Employee screen. Basic user permissions can be enabled for folders, Connectors, and the personal File Box, a temporary file storage location used when sending or requesting files from ShareFile. Connected applications and devices can also be configured. Employees can be granted administrative permissions as well, including modification and management of other users, access to reporting tools, branding, billing, configuring single sign-on, and creating/managing StorageZones and Connectors. This screen also provides the ability to downgrade or delete an employee.

Figure 3. ShareFile Create New Employee Account

ESG Lab created a Shared Folder called ESG_TEST in the ShareFile repository on Isilon, and populated it with four identical folders (esg_fs01, esg_fs02, esg_fs03, esg_fs04), each containing 26.7MB of file data for testing. Next, we explored the interface and permission/notification settings for many features including accounts, subdomains, file versioning and retention, and passwords/security/single sign-on/SAML. ShareFile help is available for most settings from an intuitive question mark icon.

Data is stored in the ShareFile repository as object storage. The metadata is stripped out and stored in Citrix data centers for up to three years to aid restore. Figure 4 shows the StorageZone screen for the Isilonrepo27 StorageZone used in this testing. A pie chart depicts the amount of used and free storage, along with network and file activity column charts. Below that are general health and heartbeat details, and buttons for editing, recovering/reconciling files, and deleting the StorageZone. The folders contained in the StorageZone are displayed below, along with creation and capacity details. Administrators can also run reports and view/download them in multiple formats (html, .pdf, .csv, xlsx).

ESG Lab Review: Secure, Scalable File Sharing Solution: Citrix ShareFile on EMC Isilon 6

© 2015 by The Enterprise Strategy Group, Inc. All Rights Reserved.

Figure 4. ShareFile on Isilon StorageZone

Configuring Device Security

Administrators can configure all mobile devices at the account level. This means that individual users may have different personas depending on whether they are accessing ShareFile from a desktop/laptop or smartphone/tablet. ShareFile provides Standard, Secure, Online Only, and Custom security settings for mobile devices. Each setting configures a device self-destruct capability, enabling automatic account removal based on extended time without logging in. This prevents data from being vulnerable should a device be lost or stolen. Other settings provide external application access, offline file access, and requirements for PIN locks and logins.

User testing

Users access data via web app, desktop client, and mobile client. For testing, ESG Lab downloaded Windows and Macintosh desktop clients, enabling the My Files and Folders folder on the desktops. This folder by default syncs automatically with the ShareFile repository. Other Shared Folders can be manually created and configured to sync. ShareFile enables a range of actions that can be executed on files or folders, including e-mailing links, viewing details, moving, and deleting.

ESG Lab also downloaded the iOS mobile client to an iPhone and iPad, and the Android client to a smartphone. The mobile client enables users to connect to ShareFile data as well as to other repositories via Connectors. Whatever Connectors are available come up when the mobile client is launched, so if the user has access permission for a network share or SharePoint site connector, that folder will be displayed. These allow users to upload/download and check in/check out content. Figure 5 shows the esg_fs01 folder synced between the Mac desktop, Android phone, and iPad. The full iPad screen displays the files within the folder on the left, and on the right, ShareFile actions such as adding items to the folder; creating files, folders, or notes; uploading photos or videos; and requesting a file.

When users request a file from any device, ShareFile can access the user’s contacts, and presents an e-mail template with a preview feature and options such as sending the e-mail using ShareFile or your own e-mail client, requiring recipient log in, notification when the file has been uploaded, and upload access expiration time.

ESG Lab Review: Secure, Scalable File Sharing Solution: Citrix ShareFile on EMC Isilon 7

© 2015 by The Enterprise Strategy Group, Inc. All Rights Reserved.

Figure 5. ShareFile Shared Folder

Mobile platform

ESG Lab tested user functions on the iPad to evaluate the mobile platform. After downloading the app from the App Store and entering credentials, we noted that ShareFile includes helpful animation so users understand ways to interact with the tablet interface, such as swiping to select multiple items. We could view My Files and Folders, the ESG_TEST shared folder, and the File Box. Each folder displayed content on the left, and folder details, editable settings, and actions on the right.

The mobile platform includes lightweight versions of Microsoft Office applications. ESG Lab opened the ESG Lab Test Plan Word document from the esg_fs01 folder to view and edit. The robust mobile platform enables full document editing including standard rulers, fonts, and tools including change tracking (Figure 6). ESG Lab added some text to a heading, saved the changes, and closed the document. After uploading it back to the ShareFile repository, we viewed the document from the desktop client and confirmed that the changes were present.

ESG Lab Review: Secure, Scalable File Sharing Solution: Citrix ShareFile on EMC Isilon 8

© 2015 by The Enterprise Strategy Group, Inc. All Rights Reserved.

Figure 6. Editing a Document in ShareFile on iPad

ESG Lab viewed Word, PowerPoint, and Excel files, viewed a video, and executed a search for all .pptx files. Of particular note was a PowerPoint Practice Mode that displays the previous, current, and next slides in a presentation along with speaker notes and time counters. When we clicked the X to close the file, an exit alert appeared to prevent accidental file closure while presenting. These features, along with the ability to create and edit files, share them, and request them, demonstrate that ShareFile mobile device users get a fully functional platform on which they can do real work, not simply view documents.

Next, ESG Lab went to the web interface, logged in, and executed some uploads, downloads, deletes, a file request, and shared a file with internal and external users. Figure 7 shows the web interface with the ShareFile e-mail prepared for sharing with another employee, including notification and security settings. In the shared folder ESG_TEST, we viewed multiple versions of the ESG Lab Test Plan document that we had edited in the iPad, and were able to view current and previous versions. Users can access any previous versions and restore them as needed.

ESG Lab Review: Secure, Scalable File Sharing Solution: Citrix ShareFile on EMC Isilon 9

© 2015 by The Enterprise Strategy Group, Inc. All Rights Reserved.

Figure 7. Sending a Document with ShareFile

Microsoft Outlook Plug-in

ShareFile offers a Microsoft Outlook plug-in that can be downloaded by the user or administrator to simplify and speed file sharing and collaboration. It eases the storage challenges that arise when large files are sent through Exchange, and enables additional tracking and monitoring of file data.

Multiple options are available for using ShareFile links instead of attaching actual files. ShareFile links can be required for all e-mail attachments, used only when the user chooses to, or used automatically based on a file-size threshold. Expiration policies can also be applied. Notifications can be sent for both send and receive, and users can configure the system to allow anonymous access or to require the receiver to log in before accessing a file.

ESG Lab configured the policy to automatically use ShareFile for attachments larger than 5MB, created an e-mail in Outlook, and dragged a large video file from ShareFile in the body of the-mail for sharing. ShareFile turned the attachment into a link. Once a copy of the file was temporarily stored in the sender’s File Box, the e-mail was sent. The recipient received the e-mail and clicked the green Download Attachments button; this link took the recipient to the File

ESG Lab Review: Secure, Scalable File Sharing Solution: Citrix ShareFile on EMC Isilon 10

© 2015 by The Enterprise Strategy Group, Inc. All Rights Reserved.

box for log in and download. The File Box is also used when ShareFile users request a file; recipients get a link directing them to a secure page for upload. The policy and received e-mail are shown in Figure 8.

Figure 8. Microsoft Outlook Plug-in

Why This Matters

If organizations want to stop employees from using unsecure public cloud file sharing solutions that increase business data vulnerabilities, they must provide an enterprise file sync and sharing alternative that is easy for users and delivers the features they need, with access from any device they choose. At the same time, these solutions must provide the ability for IT to track and manage users and data and have control over how data is stored, changed, shared, and expired.

The Citrix ShareFile on EMC Isilon solution starts with private cloud storage so data remains protected behind a corporate firewall. Citrix ShareFile provides a wide range of configurations for users and administrators, but remains simple to use and manage, while EMC Isilon provides a scalable, secure, high performance system for data storage. ESG Lab validated the ease of use for administrators and employees, including simple navigation, robust reporting, device and data security features, file syncing, and collaboration. The mobile platform enables users to actually do real work, not just view files, and the Outlook plug-in simplifies ShareFile collaboration while freeing up Exchange. These EFSS application and storage system features make Citrix ShareFile on EMC Isilon truly an enterprise-class EFSS solution.

ESG Lab Review: Secure, Scalable File Sharing Solution: Citrix ShareFile on EMC Isilon 11

© 2015 by The Enterprise Strategy Group, Inc. All Rights Reserved.

Efficiency, Scalability, and Security: Isilon and ShareFile

There are numerous benefits to using EMC Isilon private cloud storage for an EFSS solution. An Isilon private cloud keeps data on-premises, eliminating the vulnerabilities of public cloud solutions. In addition, Isilon’s storage efficiency and non-disruptive scalability can dramatically reduce the impacts of continual file data growth.

Efficiency

Duplication is a common problem with file data, resulting in organizations spending more for storage and storage management than necessary. For example, what happens when a corporate overview presentation is sent to every employee? If you have 1,000 employees, then 1,000 copies are in the e-mail system, and 1,000 employees may save the presentation to their file share, and 1,000 copies may be backed up and replicated for disaster recovery. Isilon SmartDedupe eliminates redundant data, making storage more efficient, less expensive, and easier to manage. Deduplication rates are dependent on data types, so every organization’s experience will differ—for example, image and video files may have little duplicate data, while typical office documents may have a lot. With EFSS solutions, every change to a file creates a new version—think about how many versions of files your organization generates. With Isilon, the dedupe percentage will increase as changes are made, versions are created, and more files are added, reducing storage capacity needs and costs.

ESG Lab tested deduplication by storing four identical folders on the ShareFile Repository on Isilon. Each folder contained 26.7MB of data including documents, spreadsheets, presentations, and video, for a total of 106.8MB. The Isilon cluster stored on a single copy of each file reducing capacity needs by 75%.

Figure 9. EMC Isilon Deduplication

Scalability

A key benefit of the Isilon OneFS operating system for EFFS is the ability to create a unified storage pool that scales easily while remaining a single file system. Isilon has a modular, scale-out architecture: as nodes are added, capacity grows organically and automatically load balances data, so growth does not increase management effort. In addition, adding nodes increases throughput as well as storage capacity.

The advantage of this type of scalability is that organizations can consolidate file data storage and eliminate the silos of storage that result in additional management and data migrations. EFSS data growth is easy to accommodate and can

ESG Lab Review: Secure, Scalable File Sharing Solution: Citrix ShareFile on EMC Isilon 12

© 2015 by The Enterprise Strategy Group, Inc. All Rights Reserved.

reside in the same storage as other data stores. Organizations can be flexible and grow as their needs grow, instead of having to overprovision up front to avoid disruptive data migrations in the future.

ESG Lab testing started with a three-node Isilon cluster. Multiple workloads in addition to the ShareFile repository were running on the cluster, including a virtual machine data store executing Isilon SyncIQ replication testing, multiple virtual machines booting and accessing data, and video servers archiving video files. We added a new node to the cluster in only a few clicks while all workloads continued uninterrupted.

Figure 10. Non-disruptive Scaling and Automatic Load Balancing

Security

The security advantages are a primary reason that organizations deploy EFSS using an on-premises private cloud. All data is stored behind the company firewall, where corporate security precautions remain in play. On the Isilon side, Isilon SmartLock can protect data from accidental, premature, or malicious changes or deletions, meeting the strictest industry compliance and governance regulations. Isilon Data at Rest Encryption and self-encrypting drives are also options for added security.

ShareFile security features include selective remote wipe to destroy ShareFile data and passwords on mobile devices, device locking and restriction, and a “poison pill” feature that can implement data expiration policies and activate audit controls on mobile devices. In the Isilon private cloud StorageZone deployment, the ShareFile cloud application tier stores only metadata, so no data is vulnerable in the public cloud.

Citrix ShareFile authenticates upload/download requests, and the StorageZone generates a one-time-use download token that enables the client to connect to the StorageZone for file retrieval. Also, data is encrypted at rest in the StorageZone and cannot be viewed without the customer-managed key. Using a file from our test data set, ESG Lab viewed the metadata in the ShareFile application tier and the encrypted data on Isilon. As shown in Figure 11, the metadata provided no information about the file, and the encrypted file was unreadable.

ESG Lab Review: Secure, Scalable File Sharing Solution: Citrix ShareFile on EMC Isilon 13

© 2015 by The Enterprise Strategy Group, Inc. All Rights Reserved.

Figure 11. Data Security

Why This Matters

According to ESG research, the factors most often cited as driving on-premises data storage for file sharing and collaboration solutions were flexibility and control, the belief that it would provide better data security, and concern over public cloud data accessibility.3 Security breaches and malware attacks at well-known public cloud OFS deployments highlight the vulnerabilities of these solutions for business data. In addition, organizations need a resilient storage platform that scales easily and stores growing file data efficiently and cost-effectively.

ESG Lab validated the efficiency, scalability, and security of the Citrix ShareFile on EMC Isilon solution. Isilon deduplication efficiently stores growing file data to minimize storage and management costs. ESG Lab validated that Isilon nodes can be added quickly and non-disruptively, and load balance across the storage pool to ensure high performance. Isilon increases data security with SmartLock protection, encryption, and self-encrypting drives, while numerous ShareFile features protect data from loss or leakage. With this level of protection, ESG Lab, as expected, was unable to read the metadata in the ShareFile cloud or the encrypted file on Isilon.

3Source: ESG Research Report, Online File Sharing and Collaboration: Deployment Model Trends, February 2014.

ESG Lab Review: Secure, Scalable File Sharing Solution: Citrix ShareFile on EMC Isilon 14

© 2015 by The Enterprise Strategy Group, Inc. All Rights Reserved.

The Bigger Truth

Business data has always been essential to success, but more recently it has become clear how data can act as currency. Cyber attacks are on the rise, as any cursory review of any newspaper will tell you, and cybercriminals are both selling data and holding up company data for ransom. Data vulnerabilities are costing organizations in revenue, reputation harm, and legal fines. At the same time, public cloud solutions for file sharing and collaboration have become mainstream, and employees are using them not just for personal data, but business data.

The intersection of these trends leaves organizations in a difficult position: employees must have file sync and sharing and collaboration to remain productive, but consumer file sharing solutions were not built with security in mind. According to ESG research, the vast majority of corporate file sharing accounts still use public cloud solutions like Dropbox. However, given the challenges of security and lack of control, when asked if they would be interested in a solution that stored all or some of its file data on-premises, a whopping 97% of respondents were interested.4

The Citrix ShareFile on EMC Isilon enterprise file sync and sharing solution brings together well-known leaders, Citrix in mobility and virtualization, and EMC in storage, with its flagship Isilon scale-out NAS solution. Isilon was designed for performance, scale, and availability—essential characteristics for a successful EFSS deployment. Automated load balancing, tuning, and tiering make data highly available, which EFSS solutions need to keep users in the private cloud and prevent them from going to public solutions. ShareFile is a secure, full-featured EFSS solution that is easy for both users and administrators, and delivers productivity and collaboration for file data across multiple devices, with full IT management and control. Data remains in the private Isilon cloud behind the corporate firewall, and data requests are securely managed.

The Citrix ShareFile on EMC Isilon solution provides organizations with enterprise-class file sync and sharing functionality that maintains data securely in a private cloud environment. The joint solution brings together two industry leaders, providing for what corporate EFSS users and IT really need: productivity and collaboration across devices with complete security, massive scalability without disruption, cost-reducing storage efficiency, and full IT control.

The goal of ESG Lab reports is to educate IT professionals about data center technology products for companies of all types and sizes. ESG Lab reports are not meant to replace the evaluation process that should be conducted before making purchasing decisions, but rather to provide insight into these emerging technologies. Our objective is to go over some of the more valuable feature/functions of products, show how they can be used to solve real customer problems and identify any areas needing improvement. ESG Lab’s expert third-party perspective is based on our own hands-on testing as well as on interviews with customers who use these products in production environments. This ESG Lab report was sponsored by EMC and Citrix.

All trademark names are property of their respective companies. Information contained in this publication has been obtained by sources The Enterprise Strategy Group (ESG) considers to be reliable but is not warranted by ESG. This publication may contain opinions of ESG, which are subject to change from time to time. This publication is copyrighted by The Enterprise Strategy Group, Inc. Any reproduction or redistribution of this publication, in whole or in part, whether in hard-copy format, electronically, or otherwise to persons not authorized to receive it, without the express consent of The Enterprise Strategy Group, Inc., is in violation of U.S. copyright law and will be subject to an action for civil damages and, if applicable, criminal prosecution. Should you have any questions, please contact ESG Client Relations at 508.482.0188.

4 Source: ESG Research Report, Online File Sharing and Collaboration: Deployment Model Trends, February 2014.