Virtualization Security Assessment

Michael T. Hoesing · Information Security Journal A Global Perspective · 2009

Enterprises have been increasingly adopting server virtualization technologies in recent years. Security risk identification and related controls have also been receiving increased discussion lately. i iGartner research paper G00144828 (requires a subscription) Also, guidance is available on virtualization security configurations from independent groups, such as benchmarks from the Center for Internet Security ii ii http://www.cisecurity.org/benchmarks.html and the virtualization vendors. iii iii http://www.vmware.com/pdf/vi3_security_hardening_wp.pdf This writing will revisit the risks and controls, which will be a basis for discussion of assessment techniques. As security assessors, auditors and compliance validators see more of the physical environment disappearing and being replaced by the virtual foundation, gathering the necessary metrics from virtual environment will be a key part of assurance activities. This discussion will be limited to the VMware ESX virtualization product but some principles may have applicability to other vendors' products. Also, any assessment techniques or tools mentioned are intended to be a starting point and not a comprehensive list of possible assessment approaches, nor a “best of” list of tools. In adherence to solid change management practices, any items discussed herein should be thoroughly tested in an organization's lab, compared to organization policy, and aligned with business objectives before consideration for adoption in a production environment.

Read the paper · More papers on PaperTik