Securing Virtual Machines Starts With Sound Policies

Virtualization comes with security risks. Get a handle on them by enforcing the same policies you use to secure physical servers.

CONNECTIONS
Forrester Research Inc.
WorkflowOne
Kelley Blue Book Co. Inc.
Tue, December 23, 2008CIO The ease and speed of deploying a virtualized environment has allowed some IT professionals to overlook security concerns that may be brewing up in the cloud.

At WorkflowOne, a provider of marketing services, the IT department realized it had to play catch-up to address new security risks. The potential for a sudden appearance of several virtual servers caused confusion and alarm among the security team, says John Dattalo, an information security analyst with the company. One feared scenario: That the team would come back from lunch to 10 new servers and not know where they came from or what they were for.

So, where should you start? The answer is more simple than you might think: exactly where you would in a conventional environment. "Having a strong [security] policy and adhering to and enforcing that policy are the first steps," Dattalo says. Making sure your processes are up to date is also important, says Natalie Lambert, an analyst with Forrester Research. When virtualization first became popular, few companies included security in their assessments of whether to deploy the technology. But now IT managers are seeing the risks and taking the steps to correct the oversight, Dattalo adds.

Remember the Basics

Access control stands as one of virtualization's greatest risks, says Dattalo, because someone with access to a physical server running many virtual machines "could potentially take down the entire set." Forrester's Lambert agrees: "Virtual machines have all the attributes of an entire file, and the physical server would not," she says, so employees would have access to more data than the company might want them to. In order to resolve this issue, Dattalo suggests putting a senior manager in charge of determining an access list, clearly spelling out which physical servers each employee needs to work with and which they don't.

Tracking and maintaining the virtual servers—and what's on them—is also key, says Dave Templeton, CIO with Kelley Blue Book, which provides car sales information. Templeton has added 225 virtual servers in the past 18 months. "There are the same security concerns" as with dedicated servers, he says, "but the provisioning is so much faster that you need to be more on top of things."

Currently, Templeton and his director of IT, Grant Leathers, are looking at a tool that maps every virtual machine and physical server in their data centers. With the speed virtualization offers, the need for this visibility is more important than ever. It's much harder to map what's on your virtual systems after you deploy them when you have hundreds of machines to look after, he says. Templeton suggests having an infrastructure team tightly managing the installation and support of the devices both on the rack and in the cloud, instead of trying to figure out the mapping later.

Virtualization

Loading...
Security MarketSpace
Practical Approaches for Securing Web Applications
Enterprises understand the importance of securing web applications to protect critical corporate and customer data. What many don't understand, is how to implement a robust process for integrating security and risk management throughout the web application software development lifecycle. Learn more »
An Executive's Guide to Web Application Security
Since so many Web sites contain vulnerabilities, hackers can leverage a relatively simple exploit to gain access to a wealth of sensitive information, such as credit card data, social security numbers and health records. It's more important than ever to examine your Web application security, assess your vulnerability and take action to protect your business. Learn more »
Web Application Vulnerabilities
Security managers may work for midsize or large organizations; they may operate from anywhere on the globe. But inevitably, they share a common goal: to better manage the risks associated with their business infrastructure. Increasingly, Web application security plays a significant role in achieving that goal. Learn more »
Retooling IT for a Mobile Workforce
Check out this research note from IDC for guidance. Learn more »
Today's Risky Data Environment
This paper explains how an IT and security service provider can provide a practical, manageable and reliable solution. Learn more »
Business Continuity - Are You Always Open for Business?
This Oracle business brief explains how mid-sized can improve performance by creating an IT infrastructure that makes working faster, easier and more effective. Learn more »
 
SPONSORED LINKS
 

Making Consumer Two-Factor Authentication Simple and Cost-Effective

Mining the Cloud to Ease the Enterprise Compliance Burden

Solve Five Key IT Security Challenges with Cloud-Based Authentication

White Paper: Managed Security for a Not-So-Secure World

Secure Email and Web-Based Communication from Evolving Attacks

WagerWorks Takes Fraudsters Out of the Game using iovation

White Paper: A Security Blueprint Delivered From within the Network

Return on Information: Google Enterprise Search pays you back

Cut Costs & Green Your IT Operations with PC Power Management

White Paper: 4 Customer Service Myths

White Paper: Improve Agility with Operational Responsiveness

White Paper: Legacy Tools: Not Built for the Helpdesk

Taking a Seat at the Executive Table: The Reality of Virtualization

White Paper: Next Generation Remote Infrastructure Management

Seven Design Requirements for Web 2.0 Threat Protection

Increase UPS efficiency without sacrificing protection.

Learn how advanced forecasting tools can deliver significant business results for global corporations.

Lower IT Costs with Oracle Database 11g Release 2

White Paper: Visibility and the New Normal of Mobile Work

Taking the Service Desk to the Next Level

Learn about The Information Technology Infrastructure Library.

Return on Information: Google Enterprise Search pays you back. Get the facts.

VMware. The source for Business Infrastructure Virtualization.

ShoreTel tells businesses to untangle from competitors' complexity and turn to its brilliantly simple UC solution

Top Five CIO Challenges

Authentication as a Service by Forrester Research

Cloud-Based Authentication for Next-Generation Extranets

Mobile Security: The Essential Ingredient for Today's Enterprise

IDC White Paper: CCM for IT Compliance and Risk Management

Keeping Your Members Safe from Online Scams and Predators

Learn about the growing threat of insider data theft.

Upgrading to VMware vSphere with vWire

Maximizing website Return on Information with high-quality search

See how AT&T can help protect your network.

Webcast: Unleashing the Power of Customer Data

White Paper: 5 Best Practices for Smartphone Support

Global Research: CIOs Weigh In On Virtualization

5 Key Virtualization Management Challenges

The Total Economic Impact of Network Security Intrusion Prevention

Generation Remote Infrastructure Management - Changing the Paradigm

Cloud-Based Email Management: Opinion Shifts In Favor

eBook: How Can You Make Your People Productive Anywhere?

Achieving Business Agility with Application Grid

Ready to virtualize tier one applications? Check your virtualization maturity.

Seven Ways ITIL Can Help You in an Economic Downturn

Tips for successful virtualization management.

AT&T Synaptic Storage as a Service. Expand on demand

Trend Micro ranked #1 against real-world malware. Read more.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

Streamline IT Costs. Boost Performance with WAN Optimization.

 
 
RESOURCE CENTER