Audit and Improve Virtual Server Security: Five Tips

Bad physical networking decisions. Unpatched systems. Too much access to virtual server management consoles. These and other problems can degrade the security of your virtual servers. If you're ready to improve virtual server security, consider this five-step checklist as a start.

By Carol Sliwa

Wed, May 07, 2008CIO On the surface, security questions surrounding virtual servers don't seem much different than those for the physical machines on which they run. In fact, starting a virtual security audit by keeping in mind what you've already learned in the physical world is an excellent approach. Security analysts say the same practices, principles and basic common sense apply for a group of virtual servers as for any physical server farm. But, IT managers also need to factor in some additional considerations, due to the unique characteristics of the virtual world.

One example: software can be deployed so much more quickly using virtual machines that some steps in the typical provisioning process may have been eliminated, says Paul Love, director of information security at Standard Insurance in Portland, Ore. That, in turn, requires IT departments to make sure the necessary controls and oversight are in place, with the truncated time frame in mind.

"With virtual machines, it's very helpful to pay attention to the actual configuration of the system," Love says. "You need to really have a stable build so that when you deploy a thousand versions of it, they all meet management's requirements for what controls should be in place."

When Love's team audits security for its virtual server environment, it doesn't introduce new steps so much as extend the ones it already has for physical servers, Love says. That includes looking at the interactions among systems and ensuring that the operating system on which the virtual machine runs is secure and encounters no "configuration drift."

"We have to work very closely with change management," Love says.

As background research for auditing and improving your virtual security, you may want to consult guidance for securing virtual server environments that's available from the Center for Internet Security, the Defense Information Systems Agency and virtual server leader VMware.

"They [IT leaders] need to read these guides and come up with a summary set of lock-down and hardening policies that are customized for their environments," says Nand Mulchandani, senior director of product management and marketing at VMware. "If you just do that one thing, you will be vastly more secure and safe."

Virtual security tools can also help, but analysts warn clients to first consider the products they already use before buying new ones specifically designed for virtual servers. There are already 10 to 15 vendors offering VM-specific security tools, and that figure will probably rise to 30 by year's end, says Chris Christiansen, an analyst at IDC (a sister company to CXO Media).

Loading...
Virtualization Vendor Matrix

Find out what vendors offer the products you need.

View the Vendor Matrix »
Virtualization ABCs

Get up to speed on virtualization.

Learn More »
Virtualization MarketSpace
White Papers
Learn how to address key cloud computing challenges
Learn how your organization can face the challenges of: lack of interoperability, security, compliance and application compatibility. Learn more »
VMware: Clearing the fog, a look into the Clouds
Read about VMware's compelling vision & set of products that can help clarify all of the confusion surrounding Cloud Computing. Learn more »
Cloud Computing: A fundamentally new way to deploy IT services
Learn how the VMware vCloud initiative enables you to move to the cloud how you want, when you want, and as much as you want. Learn more »
Calculate Your Specific Potential Virtualization Savings
Discover how organizations are reducing operational costs, and improving efficiency and availability. Learn more »
Forecast: Cloud Computing Looms Big on the Horizon
Read this Executive Guide to learn more about what IT leaders are saying about "Cloud Computing". This is one time when it makes good, practical business sense to have your head in the clouds. Learn more »
 
SPONSORED LINKS
 

Developing A Dynamic, Real-Time IT Infrastructure

Mid-Sized Company CIO Community: infoBOOM!

Read about virtualization and consolidation effort best practices

Building the Virtualized Enterprise with VMware Infrastructure

8 Key Ingredients to Building an Internal Cloud

White Paper: The Building Blocks for Cloud Computing

Taking the Service Desk to the Next Level

Why Data Loss is Increasing--and What You Can Do About It

Data Loss Prevention: A Better Way to Approach Security

Learn how to managing client systems in the enterprise.

Enterprise PBX Buyer's Guide

Secondary Market Primer: Your Network at Half Price

Top-line Performance that's Bottom-line Efficient

Accenture: Outsourcing for uncertain times. Click to learn more.

Learn about the VMware vSphere (TM) & Intel (R) Xeon (R) Processor 5500 Series

Data Center Optimization: Three Key Strategies

Oracle WebLogic Server Technical Demo

Data Grids and Service-Oriented Architecture

Achieving the Impossible: Unlimited Application Scalability

A Middleware Foundation for Application Grid

Tips for successful virtualization management.

Smart Decisions: The Role of Key Performance Indicators

Gartner Shares Predictions for 2009

Introducing the new HP ProLiant G6 server family

Accenture: Outsourcing for Competitive Advantage. More...

Cloud Computing: Read about VMware's compelling vision & set of products

White Paper: 8 Key Ingredients to Building an Internal Cloud

Learn how a virtualized enterprise can help your company reduce costs

Why Isn't Server Virtualization Saving Us More?

Bottom-Line Benefits of Virtualization

A CIO Executive Guide: Cloud Computing Looms Big on the Horizon

Seven Ways ITIL Can Help You in an Economic Downturn

Maximizing the Business Value of the PC Infrastructure

Communications and Collaboration Needs at Business Organizations

Using Open Source to Deploy Web Applications

Enterprise PBX Comparison Guide

Getting Value from Outdated Networking Equipment

Accenture IT Consulting: Logical meets technological. More . . .

Stop Application Fraud at the Source with Device Reputation

Top 10 Business and IT Drivers for the Wealth Management Sector

Oracle's Application Grid Technical Demo

Next-Generation Application Servers and Infrastructure

Application Infrastructure at Enterprise Organizations

Achieving Business Agility with Application Grid

Learn about The Information Technology Infrastructure Library.

Achieving Pervasive Performance Management

Automating the Generation and Secure Distribution of Excel Reports

Get Google Enterprise Search for your business information.

Accenture IT Consulting: Enabling high performance. More...

Top Five CIO Challenges

 
 
RESOURCE CENTER