Sunday | 7 September, 2008
CIO
Real Risks Inside Every Virtual Box
What are the biggest virtualization security risks now and how can you combat them? It’s time to separate fact from fiction and get down to work
Laurianne McLaughlin 07 March, 2008 15:19:42

Related Features
  • +

    SharePoint 2007: A Tool for All Reasons 04 February, 2008 12:56:06

    SharePoint 2007 packs in a sometimes confusing array of features from workflow to search. Here’s how smart IT leaders are making this
    As the technology partner (head of IT) at global law firm Bryan Cave, John Alber saw increasing resources being devoted to keeping multiple information systems integrated and the data flowing among them. Over time, the law firm brought in what it considered the best tools to handle tasks such as document repositories, e-mail management, conflict-of-interest databases and calendar management, to help attorneys and support staff research, collaborate and stay abreast of case developments
  • +

    Getting Your Vendors to Flock Together 04 February, 2008 12:53:09

    For better deals and stronger relationships, combine IT, legal and procurement experts in a vendor management office
    Keeping track of bids, vendor performance, previous contract terms, alternative providers and technology differences was taking too much time for Bernard "Bud" Mathaisel as he settled in as CIO of electronics manufacturer Solectron in 1999
  • +

    Why You Need More Than One Software Vendor 14 January, 2008 12:58:31

    The conventional wisdom is that it's always better to have fewer software vendors - or even a single vendor - to manage than it is to use multiple vendors.
    Lining up a single vendor to supply most of your software seems easy but isn't always smart, says an IT management expert. With fewer vendors to choose from these days, it's best to hedge your bets
  • +

    5 IT Projects That Need Your Attention Right Now 05 November, 2007 14:25:06

    You have only so much funding and time, so don’t waste either of them. These projects can make you a hero or at least can save you from one of those terrible “learning experiences”
    There's always too much to do. If you had an infinite budget and project schedule, or at least more resources than you have now, you could accomplish impressive things for your company. Performing triage means you need to pick IT projects that can deliver the most bang for the buck.
  • +

    Virtual Possibilities 02 October, 2007 11:58:28

    Smart CIOs are using virtualization for more than data centre consolidation. They’re becoming masters of flexibility — delivering results for the business like lightning-fast provisioning and greatly improved disaster recovery
    There isn't much about Tom Sanzone that bespeaks drama. The CIO of Credit Suisse is direct, meticulous and practical, and it doesn't seem as if he'd suffer fools gladly, an impression partly informed by his New York accent, nearly shaven head and confident demeanour
Related Stories
  • +

    The LAN turns 30, but will it reach 40? 01 February, 2008 09:20:52

    ARCnet idea came to an engineer while he was eating a meatball sandwich
    LAN technology recently passed a milestone -- it's been around for 30 years, some of them tumultuous. But while the LAN seems ubiquitous now, there are those who think its future may be more troubled than its past.
  • +

    Management tools help Mac usage at enterprises 31 January, 2008 08:52:09

    Vendors bring Macintosh management features closer to par with Windows admin capabilities
    As a senior technical support analyst at Harcourt, Randy Rowles is happy that he gets to manage the educational publisher's 1,000 or so Macintosh systems -- perhaps even a little smug, as Mac afficionados can be, about how the stability and ease of use of the systems makes his job so easy.
  • +

    Combining apps in a virtual environment 30 January, 2008 09:32:42

    Virtual matchmaking
    Managers have to be cognizant of the personalities in play on their work teams. They aim for a mix of complementary characters to maximize team depth and minimize friction and conflict. When building a virtualized server environment, network architects and administrators face the same challenge teaming up applications on a single server.
  • +

    Big IT to small biz: Listen up, little dudes! 25 January, 2008 10:55:32

    Large corporations have a lot to teach small businesses -- like these six lessons (some painfully learned) from the big boys on the tech block
    It's one of the great truths of capitalism: Businesses want to grow. Small businesses want to become midsize businesses, and midsize ones want to get big.
  • +

    Apple growth will draw malware attacks 22 January, 2008 09:08:48

    Mac OS X is safer today -- but not necessarily more secure for the long term -- than Windows
    As Apple continues to grow its worldwide market share and the company's products find their way into more business environments, attackers are certain to follow and create greater volumes of exploits aimed at vulnerabilities in the company's software, security experts contend.
Additional Resources
Executive Guides
Whitepapers

Newsletter Subscription

Sign up for our CIO newsletters!
Weekly coverage of the issues that impact corporate and government information
RSS Feeds

VIRTUALIZATION | Last year, the big question about virtualization in data centres was: "How much money and time will this save us?" This year, the big question will be: "How secure are we?"

It's an extremely tough question to answer. A slew of vendors and consultants trying to sell security products and services have conflicting opinions about the risks and how to prevent them. Simultaneously, some security researchers are hyping theoretical risks such as the possible emergence of malware targeted at hypervisors (a threat that has yet to appear in the real world). "There's a lot of noise out there on virtualization," says Chris Wolf, senior analyst for market research firm Burton Group. "It can be distracting."

Adding fuel to the hype is that fact that many IT organizations say they prioritized operational speed over most other factors, including security planning, when they started creating hundreds of new VMs in 2007. (That's not surprising, when you consider that most enterprises started with virtualization on their testing and application development boxes, not their servers running core business apps.)

"We're finding security is the forgotten stepchild in the virtualization build-out," says Stephen Elliott, IDC's research director for enterprise systems management software. "That's scary when you think about the number of production-level VMs." According to IDC, 75 percent of companies with 1000 or more employees are employing virtualization today.

And through 2009, 60 percent of production VMs will be less secure than their physical counterparts, Gartner VP Neil MacDonald predicted in a presentation at Gartner's October 2007 Symposium/ITxpo.

But much of the discussion about virtualization security has been flawed to date, says security expert Chris Hoff, because people often frame the discussion by asking whether virtual servers are more or less secure than physical ones.

That's the wrong question, says Hoff, who blogs frequently on this topic and serves as chief architect for security innovation at Unisys. The right question, he says, is: "Are you applying what you already know about security to your virtualized environment?"

"People get wound up about theoreticals . . . when in reality there's a clear set of things you can do today," Hoff says. Certainly, virtualization does introduce some new security concerns, but first things first, he says. "We have to be pragmatic. Let's make sure we architect the virtual network as well as we architect the physical networking."

As an example, he points to a virtualization management tool such as VMware's VMotion, which is helpful for moving VMs around in times of machine trouble, but which can also allow someone with admin rights to combine two VMs that, in the physical world, would have been carefully separated in terms of network traffic for security reasons.

Some IT organizations are making a fundamental mistake right now: They're letting the server group run the virtualization effort almost single-handedly - leaving the IT team's security, storage and networking experts out of the loop. This can create security problems that have nothing to do with inherent weaknesses of the virtualization technology or products. "This is a perfect opportunity to bring the teams together," Hoff says.

"Virtualization is 90 percent planning," says Burton Group's Wolf. "The planning has to include the whole team, including the network, security and storage teams."

But the fact is, most IT teams ran fast with virtualization and now must play catch-up. What if you missed that opportunity to plan with all your experts, and you're starting to worry more as you expand your number of VMs and put higher-profile apps on those VMs?

"To catch up, start with a good audit of your virtual infrastructure," using tools or consultants, Wolf says. "Then you really have to work backwards." (Wolf suggests checking out audit tools from CiRBA and PlateSpin for this purpose.)

Here are 10 positive steps enterprises can take now to tighten virtualization security.

Market Place
 

2008 CIO Summit

19th August, 2008 Four Seasons Hotel, Sydney Developed in partnership with CIO Magazine, IDC, INTEP and the CIO Executive Council.

The world of the CIO is extremely complex and diverse. Multiple priorities demand attention and decisions are needed instantly. Individual teams need to be driven towards common goals, and businesses strive to become more mobile, agile and responsive. For CIOs, the challenge never ends.

Every year the CIO Summit identifies what is top of mind for CIOs across Australia and New Zealand, and offers insight for CIO benchmarking and vendor strategic planning alike.

Recent IDC research shows that over 59% of CIO's believe that 'to achieve their business strategies, technology should be used more aggressively than today.'

Join us on August 19th to discover how this is possible with the latest technologies including Virtualisation, Web 2.0, IP Surveillance and Software as a Service (Saas).

Click here for registration.

Click here for more information.

Please email Denyse_Robertson@idg.com.au for further information.

  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    Information security governance: Centralized vs. distributed 05 September, 2008 10:15:00

    Should security policies, procedures and processes be managed within a central body, or distributed at an individual level? You need to find the middle ground.
    The management of information risk has become a significant topic for all organizations, small and large alike. But for the large, multi-divisional organization, it poses the additional challenge of determining how to deploy an information security governance program among what are often disparate business units. Should the policies, procedures, and processes that define the program be developed and managed within a central, corporate body? Or perhaps responsibility would be better placed at the individual unit level? Is there a workable middle-ground?
  • +

    DNS error brings Sophos antivirus updates to a halt 05 September, 2008 13:40:00

    Optus, Internode and Equinix affected among others.
    A sporadic Domain Name Server (DNS) error has blocked Sophos anti-virus updates around the world.
  • +

    Ouch! Security pros' worst mistakes 04 September, 2008 08:05:00

    We've all done regrettable things on the job, but does any valuable wisdom come of it? Four security pros candidly explain their biggest blunders and what they learned in the process
    It was a mistake so bad the person who made it asked that his name and company not be mentioned here. Let's call him Frank.
  • +

    Security ROI: Fact or Fiction? 03 September, 2008 08:32:00

    Bruce Schneier says ROI is a big deal in business, but it's a misnomer in security. Make sure your financial calculations are based on good data and sound methodologies.
    Return on investment, or ROI, is a big deal in business. Any business venture needs to demonstrate a positive return on investment, and a good one at that, in order to be viable.
  • +

    Information Security and the Importance of Context 01 September, 2008 10:00:00

    Those entrusted with information security must raise their contextual awareness
    When the US Transportation Security Administration (TSA) was first created, it created a sudden need for tens of thousands of screeners. Getting a job as an airport screener was a pretty easy process. It seemed as though if you had a pulse, you were in. Jump forward to 2008 and becoming a screener is a bit harder as the TSA has instituted background checks, has upped the educational requirement to include a high school diploma or GED, and added other significant requirements.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

Web Security SaaS: The Next Generation of Web Security

Discover the latest web security SaaS solutions. Learn how to increase overall security effectiveness and reduce the burden on your IT department. Uncover the security challenges facing SMB environments today and identify the critical elements that can provide you with lower-cost and easier-to-manage web security solutions.

Sponsored Links