YOUR FEEDBACK
NGASI Releases AppServer Manager 8.1
Dave Jenkins wrote: The remote server management is a welcomed added feature...
SOA World Conference
Virtualization Conference
$200 Savings Expire May 16, 2008... – Register Today!

SYS-CON.TV

2007 West
GOLD SPONSORS:
Active Endpoints
Your SOA Needs BPEL for Orchestration
BEA
Virtualized SOA: Adaptive Infrastructure for Demanding Applications
Nexaweb
Overcoming Bandwidth Challenges with Nexaweb
TIBCO
What is Service Virtualization?
SILVER SPONSORS:
WSO2
Using Web Services Technologies and FOSS Solutions
Click For 2007 East
Event Webcasts

2008 East
PLATINUM SPONSORS:
Appcelerator
Think Fast: Accelerate AJAX Development with Appcelerator
GOLD SPONSORS:
DreamFace Interactive
The Ultimate Framework for Creating Personalized Web 2.0 Mashups
ICEsoft
AJAX and Social Computing for the Enterprise
Kaazing
Enterprise Comet: Real–Time, Real–Time, or Real–Time Web 2.0?
Nexaweb
Now Playing: Desktop Apps in the Browser!
Sun
jMaki as an AJAX Mashup Framework
POWER PANELS:
The Business Value
of RIAs
What Lies Beyond AJAX?
KEYNOTES:
Douglas Crockford
Can We Fix the Web?
Anthony Franco
2008: The Year of the RIA
Click For 2007 Event Webcasts
TOP THREE LINKS YOU MUST CLICK ON


Virtualization and Security: Are We Missing the Wood for the Trees?
In a virtual world it's harder to keep track of what business activities happen where

Digg This!

Forrester's Security & Risk Management Blog

I've sat through a number of presentations and sessions about security and virtualization in recent times and can't help thinking that people are falling into the old trap of going after the possible rather than the probable.

Most discussions I've seen around security and virtualization center around subtle threats to the hypervisor layer, and whether it's possible to jump from one virtual machine to another. Then there are the circular discussions about whether it's provably more secure to perform AV and intrusion inspection from inside the virtual machine, or have the host perform all the functions.

All pretty tedious if you ask me. I reckon we've some much bigger problems in a virtual world.

Isn't it more of a problem that in a virtual world it's harder to keep track of what business activities happen where? Isn't the patch and vulnerability management process exponentially more complex when you're instantiating and destroying virtual machines left right and center? How do you determine what risks you're introducing if you move a virtual machine from one place to another? How do we track all this and demonstrate it to our friendly auditors when they come a-knocking?

I reckon we need to elevate the level of conversation to talk about the real risk consequences of virtualization, and what it does to the security business model.

Don't get me wrong, we do need to consider these more subtle virtualization threats, but rather than talking about them in isolation, we can incorporate them into wider conversation. This can then include the slew of new deployment, implementation and licensing options virtualization introduces for security services, and devise a more business oriented way to establish who does what, where, and when for optimal security and cost.


[This blog appeared originally here and appears by the kind permission of the author and Forrester Research, who retain copyright.]

About Paul Stamp
Paul Stamp is a consultant with Forrester Research.

LATEST SAAS DEVELOPER STORIES
Bluewolf Announces Insurance and Banking Industry SaaS Solutions
Bluewolf announced the availability of new insurance and banking industry Software-as-a-Service (SaaS) solutions built on the Force.com platform. Bluewolf has implemented and developed more than 1,000 SaaS solutions for organizations worldwide, including the Royal Bank of Scotlan
Virtualization Conference Keynote Webcast Live on SYS-CON.TV
Brian Stevens, the Chief Technology Officer and Vice President of Engineering of Red Hat, delivered his Virtualization Keynote 'The Future of the Virtual Enterprise' at SYS-CON's Virtualization Conference & Expo 2007 West in San Francisco. 'Virtualization is the hottest subject
3rd International Virtualization Conference & Expo: Themes & Topics
From Application Virtualization to Xen, a round-up of the virtualization themes & topics being discussed in NYC June 23-24, 2008 by the world-class speaker faculty at the 3rd International Virtualization Conference & Expo being held by SYS-CON Events in The Roosevelt Hotel, in mi
Wal-Mart To Sell $399 Ubuntu Linux-based Laptop with Google Operating System
The Ubuntu Linux-based gOS operating system from Good OS LLC (www.thinkgos.com) includes so many Google applications like Gmail, Google Docs, Google Calendar, Google News Google Maps and YouTube that it's often referred to as the Google operating system. It also includes Firefox,
Locus' ePortal Leverages SOA
Locus has been selected by the Los Angeles Board of Harbor Commissioners to perform environmental site assessment, soil and groundwater investigation and cleanup, environmental compliance assessment and environmental information management services for The Port of Los Angeles. Th
SUBSCRIBE TO THE WORLD'S MOST POWERFUL NEWSLETTERS
SUBSCRIBE TO OUR RSS FEEDS & GET YOUR SYS-CON NEWS LIVE!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

SYS-CON FEATURED WHITEPAPERS

ADS BY GOOGLE
BREAKING SAAS DEVELOPER NEWS
Bluewolf Receives a GovernmentVAR Magazine Solution Provider Award
Bluewolf (www.bluewolf.com) was awarded the small business solution provider of the yea