tfh
Volume 16, Number 15 -- April 16, 2007

Virtualization Can Hurt Security, Gartner Says

Published: April 16, 2007

by Alex Woodie

Thousands of companies are adopting virtualization to increase the utilization rates of their servers and save money. But unless these companies take pains to properly secure their virtualized IT environments, it can end up hurting their security posture, reducing their agility, and increasing costs, Gartner warned last week.

While there is a lack of uniformity and standards among virtualization technologies, there is one aspect that all virtualization products have in common, according to Gartner: They create a privileged layer that, if compromised, puts all consolidated workloads at risk. With so many eggs in one basket, it's even more important to implement good security practices to protect critical data and applications.

Unfortunately, most companies won't take these extra steps to implement strong security for virtualized environments, Gartner says, and this will have a predictable effect. The analyst group says 60 percent of production virtual machines (VMs) implemented through 2009 will be less secure than their physical counterparts.

"Many organizations mistakenly assume that their approach for securing VMs will be the same as securing any OS and thus plan to apply their existing configuration guidelines, standards and tools," says Neil MacDonald, vice president and Gartner Fellow. "While this is a start, simply applying the technologies and best practices for securing physical servers won't provide sufficient protections for VMs."

But don't fret: Gartner says there are several steps that companies can take to start securing their VMs. Companies must protect their new weakest link--the hypervisor. They must be prepared to deal with the loss of separation of duties for administrative tasks. They must take pains to ensure the proper patching and signature support for VM and VM appliance images. They must somehow work around the decreased visibility into the host operating system and its network connections, as well as into intra-VM traffic, which needs to be inspected by security software. Companies must also be ready to implement security policies that can cope with VMs that are mobile. Lastly, IT professionals will have to get creative, because the security and management tools to accomplish many of these tasks in VM environments are "immature and incomplete," Gartner says.

"Organizations need to pressure security and virtualization vendors to plug the major security gaps," MacDonald says. "Existing virtualization solutions address some of the gaps, but not all. It will take several years for the tools and vendors to evolve, as well as organizations to mature their processes and staff skills."

MacDonald will present more information on the security threats posed by virtualization technologies in a session titled "Securing Virtualization, Virtualizing Security," during the Gartner Symposium/ITxpo 2007: Emerging Trends event, which is being held in two weeks in San Francisco.



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
RJS SOFTWARE SYSTEMS

Make Your Office Paperless by Eliminating Pre-printed Forms

 

Reduce paper, printing and storage costs.
Create e-forms from scratch or from existing spool files
and text reports. Add color logos, bar codes and graphics.

 

Visit us at www.rjssoftware.com
or call us at 888-RJS-SOFT for a free 30-day demo.


Editor: Timothy Prickett Morgan
Contributing Editors: Dan Burger, Joe Hertvik, Brian Kelly, Shannon O'Donnell,
Mary Lou Roberts, Victor Rozek, Kevin Vandever, Hesh Wiener, Alex Woodie
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

Computer Keyes:  Rapidly convert *SCS printer files into black and white or full color PDF documents
COMMON:  Join us at the 2007 conference, April 29 – May 3, in Anaheim, California
VAULT400:  Securely archive data with Instant Back-Up & 24x7 Recovery

 

IT Jungle Store Top Book Picks

The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95

 

The Linux Beacon
AMD Pushes Opteron Clocks to 3 GHz, Will Miss Q1 Revenue Targets

Xandros Server 2 To Get Integrated Virtualization and Messaging

X4 Chipset from IBM Tuned for Tigerton Quad Core Xeon MPs

The X Factor: Virtualization Belongs in the System, Not in the Software

Four Hundred Stuff
Aldon Tackles Parallel Development Problems with LMi 7.5

Ricoh in Deal for AFP/IPDS Emulation

S4i Web Interfaces to Document Management Offering

CA Tweaks Job Schedulers, Positions Them as Workload Automation

Big Iron
CA Tweaks Job Schedulers, Positions Them as Workload Automation

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
Missing In Action: The Full Outer Join

Reader Feedback on One-Man System i Shops

Admin Alert: The Process and Pitfalls of Duplicating Libraries

System i PTF Guide
April 7, 2007: Volume 9, Number 14

March 31, 2007: Volume 9, Number 13

March 24, 2007: Volume 9, Number 12

March 17, 2007: Volume 9, Number 11

March 10, 2007: Volume 9, Number 10

March 3, 2007: Volume 9, Number 9

The Windows Observer
Vista's Security Honeymoon Is Over

'Longhorn' Nears the Gate

AMD Pushes Opteron Clocks to 3 GHz, Will Miss Q1 Revenue Targets

X4 Chipset from IBM Tuned for Tigerton Quad Core Xeon MPs

The Unix Guardian
Yen Explains Sun's Chip Strategy

Hello, New York? Buy IBM

Schwartz Blogs a Bit About the Dud Rock Chip on His Desk

As I See It: The Legacy

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

BCD
Vision Solutions
SafeData
COMMON
RJS Software Systems



TABLE OF CONTENTS
IBM Goes After Windows with User-Priced System i Servers

IBM Upgrades High-End System i5 Servers

Wheeling and Dealing to Move System i Iron

System i and the Web: Where We've Been and Where We're Going

But Wait, There's More:

IBM Executives' iSociety Chat: Direct Sales and a Developer Price Point . . . Massive $74 Billion Consolidation in the ERP Space . . . Lawson Sees Red Ink In Fiscal Third Quarter . . . Vendors Propose Fibre Channel Over Ethernet Standard . . . New 36 GB, 4mm Tape Drive Fills In the VXA Gap for i5 Servers . . . Virtualization Can Hurt Security, Gartner Says . . .

The Four Hundred

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement