x



Loading... Please wait...

Forum Search

Search
Latest Posts

zuohuijuan

zuohuijuan forum at Info security adviser

has added a message to the topic "Hacker Halted Conference -2010"

faiyzy

faiyzy forum at Info security adviser

has added a message to the topic "UK/Europe InfoSec Standards"

Advertising
advertise here
Introduction

Start a discussion with your peers and share your views in this online forum. Discover what people really think is happening in the industry and meet like-minded professionals.

Share your views now!

Register now to post a comment or add a response

Forum -> How secure is the current practice in virtualisation?

How secure is the current practice in virtualisation? 10-02-2009 12:07

infosecurity_europe forum at Info security adviser
Infosecurity Europe

"It may make financial sense to consolidate a processor-intensive application onto the same physical host as another that is network-intensive to better balance the use of available resources. However, such an approach may result in virtual servers running highly sensitive core business applications sitting alongside those running publicly accessible applications or websites, both on the same physical host.”  (Gary Wood, Research Director, ISF, from: How Secure is the Current Practice in Virtualisation? Computer Weekly) 

Re: How secure is the current practice in virtualisation? 20-02-2009 13:26

kkay forum at Info security adviser
KKay
Virtualisation is a good thing! Businesses should try to leverage some of the advantages of virtualisation, but in a secure way. Virtualisation can improve resilience and security.

Re: How secure is the current practice in virtualisation? 03-03-2009 14:08

bustick forum at Info security adviser
Bustick

It seems pretty risky to share services in this manner. I understand that the idea/ideal is to prevent bottlenecks and share load, but the comment at the top sounds like it has to be implimented sensibly adn very carefully or it could impact business critical services.

The security aspect of it represent other issues altogether, and one I would hope has been anticipated from the outset. Questions to be asked when looking for your solution I'd wager . . .

Re: How secure is the current practice in virtualisation? 05-03-2009 16:02

rpark forum at Info security adviser
rpark

This article talks about how security is the "forgotten stepchild" in the virtualisation buildout:

http://www.cio.com/article/154950/How_to_Find_and_Fix_Real_Security_Threats_on_Your_Virtual_Servers

Many IT organisations have placed highest priority on building out virtualised environments so it's more likely for security to fall by the wayside.

You get situations where the security people aren't involved in setting up virtualisation and have no idea how secure everything is. The server group winds up running the show, and they handle all of the networking and security tasks involved with configuring virtualisation. Since they aren't experts with these areas, it's more likely for mistakes to be made. Also, it's less likely for virtual machines to go through the standard security lifecycle, such as being scanned for vulnerabilities, patched on a regular basis, etc.

Richard Park, Sourcefire

Re: How secure is the current practice in virtualisation? 07-04-2009 10:39

agent_smith forum at Info security adviser
Agent Smith
In running a virtual environment you need to exercise the same stringent security practices as you would with physical servers, and if budget allows it, run a virtual environment in the dmz & a separate virtual env on the internal network. In all virtualisation is a good thing & the way to go, however there are now a whole new set of security policies regarding the virtual environment that need to be considered & monitored.

© 2009 Reed Exhibitions | Contact Us | Privacy Policy

Infosecurity Adviser is produced by Reed Exhibitions with thanks to Tangent Labs