Aller au contenu principal
DocumentMS

Glossary

WORM storage

Also called: write once read many, immutable storage, object lock

WORM storage is a medium that permits data to be written once and read many times, but never altered or erased before its retention period expires. Some financial recordkeeping rules require it, and cloud object lock features are the modern implementation.

WORM storage explained

Where the requirement comes from

SEC Rule 17a-4 is the best-known source. It permits certain broker-dealer records to be preserved either on a non-rewriteable, non-erasable medium, or under an audit-trail arrangement that evidences records have not been altered. That second option matters, because it means WORM media is one route to compliance rather than the only one.

Comparable requirements appear in other regimes, and organisations sometimes adopt WORM storage voluntarily for ransomware resilience — an attacker who compromises an account still cannot delete locked objects.

How it is implemented now

Rarely as optical media any more. In practice it is object lock on cloud object storage: Amazon S3 Object Lock in compliance mode, or Azure immutable blob storage. Both prevent deletion until a retention date passes, including by the account owner.

The interaction people miss

Object lock and a retention schedule must agree. If the lock period is longer than the retention period, disposal fails at the end of the schedule and the record persists past the date you committed to destroying it — which is its own compliance problem, particularly where an erasure right applies. Configure them together rather than separately.

Before designing around it

Establish which of your records are genuinely in scope. Applying immutable storage to everything is expensive, complicates erasure requests, and creates a conflict with any right to deletion — whereas applying it to the specified record types is straightforward and defensible.

FAQ

WORM storage: common questions

Is WORM storage required for all financial records?

No. It applies to specified record types under specified rules, and even then an audit-trail arrangement can be an alternative. Check which of your records are actually in scope before designing around it.

Does object lock protect against ransomware?

For locked objects, largely yes — they cannot be encrypted or deleted until the lock expires, even by a compromised administrator. It does not protect anything outside the locked bucket.

Une session de 30 minutes avec un ingénieur avant-vente, sur une arborescence et une chaîne d'approbation proches des vôtres — pas un environnement de démonstration générique.