Audit and Improve Virtual Server Security: Five Tips

Bad physical networking decisions. Unpatched systems. Too much access to virtual server management consoles. These and other problems can degrade the security of your virtual servers. If you're ready to improve virtual server security, consider this five-step checklist as a start.

By Carol Sliwa

Wed, May 07, 2008CIO On the surface, security questions surrounding virtual servers don't seem much different than those for the physical machines on which they run. In fact, starting a virtual security audit by keeping in mind what you've already learned in the physical world is an excellent approach. Security analysts say the same practices, principles and basic common sense apply for a group of virtual servers as for any physical server farm. But, IT managers also need to factor in some additional considerations, due to the unique characteristics of the virtual world.

One example: software can be deployed so much more quickly using virtual machines that some steps in the typical provisioning process may have been eliminated, says Paul Love, director of information security at Standard Insurance in Portland, Ore. That, in turn, requires IT departments to make sure the necessary controls and oversight are in place, with the truncated time frame in mind.

"With virtual machines, it's very helpful to pay attention to the actual configuration of the system," Love says. "You need to really have a stable build so that when you deploy a thousand versions of it, they all meet management's requirements for what controls should be in place."

When Love's team audits security for its virtual server environment, it doesn't introduce new steps so much as extend the ones it already has for physical servers, Love says. That includes looking at the interactions among systems and ensuring that the operating system on which the virtual machine runs is secure and encounters no "configuration drift."

"We have to work very closely with change management," Love says.

As background research for auditing and improving your virtual security, you may want to consult guidance for securing virtual server environments that's available from the Center for Internet Security, the Defense Information Systems Agency and virtual server leader VMware.

"They [IT leaders] need to read these guides and come up with a summary set of lock-down and hardening policies that are customized for their environments," says Nand Mulchandani, senior director of product management and marketing at VMware. "If you just do that one thing, you will be vastly more secure and safe."

Virtual security tools can also help, but analysts warn clients to first consider the products they already use before buying new ones specifically designed for virtual servers. There are already 10 to 15 vendors offering VM-specific security tools, and that figure will probably rise to 30 by year's end, says Chris Christiansen, an analyst at IDC (a sister company to CXO Media).

More from IT Drilldown « Back to Virtualization
CASE STUDY
Bank Scores with Server Virtualization
They say old habits die hard. It's a adage that's certainly true for ICICI Bank's senior GM and the Group CTO, Pravir Vohra. As a man who was part of the team that popularized online banking and helped create a new revenue stream for ICICI Bank, Vohra is already known as an IT leader who can make a difference. Full Story »

Loading...
Virtualization Vendor Matrix

Find out what vendors offer the products you need.

View the Vendor Matrix »
Virtualization ABCs

Get up to speed on virtualization.

Learn More »
Virtualization MarketSpace
MarketSpace White Papers
Twenty-to-One Consolidation on Intel Architecture: New Tools for Virtualization and Workload Management
Consolidation isn't easy—especially considering the costs and risks that come with bringing multiple applications and operating systems together on a single mainframe or proprietary platform... Learn more »
Building the Virtualized Enterprise with VMware Infrastructure
Many organizations struggle with their legacy IT infrastructures which are often plagued by high costs, slow response times and inconsistent management... Learn more »
TECHNOLOGY ASSESSMENT: The Impact of Virtualization Software on Operating Environments
Virtualization is a potential game-changer for modern computing. This IDC Technology Assessment discusses how virtualization technologies impact operating environments, now and in the future... Learn more »
Reducing Server Total Cost of Ownership with VMware Virtualization Software
Technology purchases are often quantified simply by hardware and software costs. But there's more to it. This TCO study takes a holistic view—considering soft dollars too, like ongoing maintenance and... Learn more »
 
SPONSORED LINKS
 

Virtualization Benchmark and TCO Analysis-Read Now

New IDG Survey Results on Data Center Automation

Get help navigating the management challenges of virtualization.

Narrow the gap between virtualization's benefits and the management risks.

Cash in on the promise of virtualization

Learn to Leverage Maximum Computing Power

Windows Vista: Essential Benefits and Deployment Strategies

Best Practices: Safe and Secure Hardware Asset Recovery

White Paper: Migrating to Windows Vista and Microsoft Office 2007 Together

White Paper: Enabling Next Generation IP Communications

White Paper: A Cohesive Network Security Approach

Why Your Firewall, VPN, and IEEE Aren't Enough to Protect Your Network

Dramatically boost network capacity and speed-up to 600 Mbps

Learn how companies are changing how they reach out to their most profitable customers.

Remote Infrastructure Management - What Your Peers are Thinking

Complementary BI: The New Approach to Business Intelligence

Unified Communications & Collaboration: Game-Changing Business Results

The ECM Paradox: Extending Local Flexibility to Strengthen Central Control

Customer Insight Yields Sales, Marketing Gains

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

File Integrity Monitoring: Prove compliance and secure your IT environments

Affordable technology-no compromise. HP server solutions

SOA Educational Library at the TIBCO SOA Resource Center

CIO Viewpoints: Migrating to Exchange 2007

Server Virtualization Benchmark Results

White Paper: The Roadmap to Data Center Automation

Find out how to manage virtualization's risks and reap the rewards.

Conquer the realities of managing virtualization

White Paper: Scaling Down HPC for Smaller Organizations

White Paper: Never Enough Compute Power?

Microsoft Windows Vista Cost and Benefit Estimator

White Paper: Efficient Desktop Application Management

White Paper: Take your Call Center to the Next Level

Is Your WLAN Helping You Comply with Security Guidelines of the PCI Standard?

White Paper: Improve Employee Efficiency and Reduce Telecom Costs

White Paper: Green Issues for Networking

Operational Excellence Is Key to Maximizing IT Investments

The Right and Wrong Master Data Management Strategies to Start Small and Grow Big

Webcast - "Into the Wild: Managing Laptops Outside the Office"

Mobility is Growing: Survey Shows Why CIOs are Concerned

Learn what it takes to build a holistic digital collaboration platform

Make Hidden Trends, Inter-Relationships and Influences Visible.

Improve delivery of product information to customers.

Renowned Engineering Institution Chooses AMD Processor-Based Servers

Corral, configure and control all your mischievous machinery with a Lantronix device server

Spend less. Get hosted UC. Get cash back. It's easy under a Cypress

Predict the future with HP Insight Power Manager

Log onto Hitachi True Stories, films inspired by the next great achievement

Earn PROFESSIONAL DOCTORATE Part-Time, Online at Syracuse University's iSchool

 
 
RESOURCE CENTER