Securing Virtual Machines Starts With Sound Policies

Virtualization comes with security risks. Get a handle on them by enforcing the same policies you use to secure physical servers.

CONNECTIONS
Forrester Research Inc.
WorkflowOne
Kelley Blue Book Co. Inc.
Tue, December 23, 2008CIO The ease and speed of deploying a virtualized environment has allowed some IT professionals to overlook security concerns that may be brewing up in the cloud.

At WorkflowOne, a provider of marketing services, the IT department realized it had to play catch-up to address new security risks. The potential for a sudden appearance of several virtual servers caused confusion and alarm among the security team, says John Dattalo, an information security analyst with the company. One feared scenario: That the team would come back from lunch to 10 new servers and not know where they came from or what they were for.

So, where should you start? The answer is more simple than you might think: exactly where you would in a conventional environment. "Having a strong [security] policy and adhering to and enforcing that policy are the first steps," Dattalo says. Making sure your processes are up to date is also important, says Natalie Lambert, an analyst with Forrester Research. When virtualization first became popular, few companies included security in their assessments of whether to deploy the technology. But now IT managers are seeing the risks and taking the steps to correct the oversight, Dattalo adds.

Remember the Basics

Access control stands as one of virtualization's greatest risks, says Dattalo, because someone with access to a physical server running many virtual machines "could potentially take down the entire set." Forrester's Lambert agrees: "Virtual machines have all the attributes of an entire file, and the physical server would not," she says, so employees would have access to more data than the company might want them to. In order to resolve this issue, Dattalo suggests putting a senior manager in charge of determining an access list, clearly spelling out which physical servers each employee needs to work with and which they don't.

Tracking and maintaining the virtual servers—and what's on them—is also key, says Dave Templeton, CIO with Kelley Blue Book, which provides car sales information. Templeton has added 225 virtual servers in the past 18 months. "There are the same security concerns" as with dedicated servers, he says, "but the provisioning is so much faster that you need to be more on top of things."

Currently, Templeton and his director of IT, Grant Leathers, are looking at a tool that maps every virtual machine and physical server in their data centers. With the speed virtualization offers, the need for this visibility is more important than ever. It's much harder to map what's on your virtual systems after you deploy them when you have hundreds of machines to look after, he says. Templeton suggests having an infrastructure team tightly managing the installation and support of the devices both on the rack and in the cloud, instead of trying to figure out the mapping later.

Virtualization

Loading...
Virtualization MarketSpace
5 Key Virtualization Management Challenges
EMA covers five challenges and investigates the critical role of management tools and processes to free up skilled staff. Learn more »
Meet Changing Business Needs in the Cloud
Learn how F5 and VMware help you orchestrate and deliver access to services in the cloud. Learn more »
Connecting to the Cloud
F5 and VMware partner to enable live application and storage migrations between datacenters and clouds. Learn more »
Optimizing Unique Data for the Client Desktop
F5 BIG-IP Local Traffic Manager helps reduce the impact on the WAN from VDI. Learn more »
The Advantages of Virtualization Infrastructure Platforms
Seamlessly optimize your virtual network and storage environment. Learn more »
Explore the Common Barriers to Virtualization
Discover best practices around furthering virtualization in a secure and compliant environment. Learn more »
Retooling IT for a Mobile Workforce
Check out this research note from IDC for guidance. Learn more »
 
SPONSORED LINKS
 

Removing Barriers To Better Server Virtualization Efficiency

Global Research: CIOs Weigh In On Virtualization

5 Key Virtualization Management Challenges

Verint Systems. Discover the Power of Intelligence in Action"

Unified Communications: Thoughts, Strategies and Predictions. Join the discussion.

Return on Information: Google Enterprise Search pays you back

Cut Costs & Green Your IT Operations with PC Power Management

Webcast: Unleashing the Power of Customer Data

White Paper: Legacy Tools: Not Built for the Helpdesk

Secure Email and Web-Based Communication from Evolving Attacks

WagerWorks Takes Fraudsters Out of the Game using iovation

Seven Design Requirements for Web 2.0 Threat Protection

Cloud-Based Email Management: Opinion Shifts In Favor

Lower IT Costs with Oracle Database 11g Release 2

White Paper: Visibility and the New Normal of Mobile Work

Taking the Service Desk to the Next Level

Learn about The Information Technology Infrastructure Library.

CA ARCserve r12.5 is More Than Backup! Download Trial Version Today

Secure & simplify your data center w/Juniper Networks.

Register for more Windows Enterprise Webcasts today.

Gartner Symposium ITxpo 2009: The World's Most Important Gathering of CIOs and Senior IT Executives

Stay informed with custom newsletters from Tech Dispenser

AT&T Synaptic Storage as a Service. Expand on demand

Trend Micro ranked #1 against real-world malware. Read more.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

White Paper: Right-Sizing Your Power Infrastructure

Taking a Seat at the Executive Table: The Reality of Virtualization

Server Consolidation: Leveraging the Benefits of Virtualization

Cisco SIO To Go for iPhone. It's like having a security expert in the palm of your hand.

Upgrading to VMware vSphere with vWire

Maximizing website Return on Information with high-quality search

See how AT&T can help protect your network.

White Paper: 5 Best Practices for Smartphone Support

White Paper: Next Generation Remote Infrastructure Management

Keeping Your Members Safe from Online Scams and Predators

The Total Economic Impact of Network Security Intrusion Prevention

Generation Remote Infrastructure Management - Changing the Paradigm

Learn how advanced forecasting tools can deliver significant business results for global corporations.

Achieving Business Agility with Application Grid

Ready to virtualize tier one applications? Check your virtualization maturity.

Seven Ways ITIL Can Help You in an Economic Downturn

Tips for successful virtualization management.

Dark Fiber from Sunesys Save on Unlimited Bandwidth with Fixed Costs.

Masters of Virtualization and Cloud Computing - Daily News

Webcast: The Costs and Challenges of Supporting Today's Information Worker

Top Five CIO Challenges

Return on Information: Google Enterprise Search pays you back. Get the facts.

VMware. The source for Business Infrastructure Virtualization.

ShoreTel tells businesses to untangle from competitors' complexity and turn to its brilliantly simple UC solution

Streamline IT Costs. Boost Performance with WAN Optimization.

 
 
RESOURCE CENTER