Securing your virtualized environment
- 23 March, 2009 08:20
- Comments
Virtualization promises to make IT departments more flexible, more efficient and -- perhaps most crucial in these tough times -- more frugal. But one advantage the technology doesn't provide is an escape from the need for strong security measures.
As soon as he began planning his Novell virtualization project, Noah Broadwater realized that he was looking at an initiative that would require both a continuation of existing security practices and an analysis of any perils that might be created by the new technology.
"It was evident that virtualization demanded a close look," says Broadwater, who is vice president of information services at New York-based children's media producer Sesame Workshop. "Above all, we had to make sure that we would be secure on all fronts."
Neil MacDonald, an analyst at Gartner Inc., says that virtualization is opening new doors for IT departments as well as for people who seek to tamper with critical data and services.
"Adopters can expect that virtualized software, like hypervisor software, will be attack targets," he says. "Therefore, virtualization security planning should be addressed at a project's inception."
Crash and Learn
With IT departments in today's crashing economy being asked to do more with less, virtualization's lure is becoming increasingly irresistible. But as some departments rush headlong toward the technology in an effort the stretch scarce dollars, the temptation arises to skimp on security.
Many thrifty managers believe that the same technologies currently used to protect conventional physical servers can simply be extended to virtualized environments. But MacDonald says that's a potentially calamitous assumption. He notes that the unwary could be trapped by threats in several areas, including software, administration, mobility, the operating system and network visibility. "There need to be policies to address these issues," he adds.
Broadwater takes some common-sense defensive steps, such as using firewall controls to limit user access and running a full array of security protocols and checks on each virtual server. In addition, Broadwater says he depends on his virtualization software vendor, Novell Inc., to supply a product that's resistant to intrusions and attacks. He says he worries about "holes in the virtualization software itself -- kernel attacks, someone attacking the host module or one of my guys making a mistake against the host server -- and then making sure that the full virtualization software is actually secure and is patched."
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Virtualization keeps server projects hot in 2009
- Quiz highlights benefits, limits of server virtualization
- Opinion: Virtualization security yields nothing so far
- Economy in turmoil: Latest news and tips on how to survive
- Virtualization Increases IT Security Pressures
- Five virtualization trends to watch - Computerworld Blogs
- Security concerns cloud virtualization deployments
- FAQ: Desktop virtualization
- Opinion: Good virtual security requires better IT teamwork
- Five steps to successful and cost-effective penetration testing
- 2-Layer BPM: Oracle's Unique Strategy Towards Exceptional Agility and Business Process Efficiencies
- Increasing Uptime and Efficiency with Switched PDUs - Two ways to use rack PDUs for more than just distributing power
- 10 Things Your Next Firewall Must Do
- A buyer’s guide to application lifecycle management (ALM) solutions
- Server and Storage Optimization Techniques
- iPhone 5 rumour rollup for the week ending February 10
- 3D mapping revives underwater city
- Academic challenges Turnbull over NBN satellite criticism
- What are you saying: Telstra’s customer service slowly improving, SA minister urging Facebook to overturn its photo ban
- In pictures: Capgemini opens new Canberra office
-
Windows Event Viewer phishing scam remains active
-
NeuroSky MindWave: Fun with Brainwaves
-
20 popular Ubuntu Linux apps you may want to try
-
Nokia N9: Why you shouldn't buy this device
-
Microsoft at a loss over Event Viewer scam
-
Microsoft Office
-
Computers for Seniors for Dummies, 2nd Edition
-
MYOB Software for Dummies 6E Australian Edition
-
Office 2007 All-In-One Desk Reference for Dummies
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies®
-
Windows 7 for Seniors for Dummies®
-
Office 2007 for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle












Comments
Post new comment