ARN

Virtualisation: Taking the risk

Facing a bumpy economic ride, many organisations are looking at how to get more out of the IT equipment they have, and what investments can bring about serious cash savings. Virtualisation has become an integral part of the solution, but it comes with a fresh set of challenges around security.

Securing virtual environments, whether it be at the desktop, server, network, application or storage level, is a crucial component to any virtual strategy. With the security threat landscape constantly evolving, putting all company resources into a centralised virtual environment without a comprehensive security game plan is a gamble no organisation should willingly take.

According to several security experts, the worst data breaches this year will come from within. RSA recently released the findings of a survey it conducted with 417 people, mostly employed in finance and technology. The results found everyday employee behaviour could trigger significant risk to sensitive business information.

“Should a security breach or violation occur, and it’s an internal one, the consequences can be more significant in a virtualised environment than a traditional one,” Frost and Sullivan ICT director, Andrew Milroy, said. “Access control has been a problem for some time, but it’s an obvious thing that has to be looked at again as companies change their architecture.”

When an organisation opts for a virtual environment, their whole architecture changes. For example, organisations might not have their security software set-up in a way to address network traffic changes, Milroy said.

“It’s not that the current security products can’t handle what’s going on,” he said. “It’s more of a cultural change of understanding how to deploy security products more effectively in this kind of architecture.

“There’s usually a lag for security to catch up with changes in the way people are using computing resources, but a lot of security firms are on to this.”

VIRTUAL MANAGEMENT

One of the biggest problems now facing organisations implementing server virtualisation across the datacentre is virtual server sprawl. IBM Australia development labs security specialist, Neil Readshaw, said this affected all aspects of management and security including basic tasks like patch management.

“You’ve got to remember that some of these virtual environments aren’t running all the time. They are dormant until work increases to the point where they need to be brought online or provisioned near real-time in response to some high work loads in the environment,” he said.

“The virtualisation layer that sits between the physical machines and these virtual environments, the hypervisor, is a new component in the environment from an attack and vulnerability point of view. It’s another component that needs to be secured within itself.”

Access control – who gets to see what and where the information is being sent – is another bane of many security managers. RSA Security country manager, Mark Pullen, recommended more scrutiny be given to managing user access privileges.

Come socialise with us! Facebook | LinkedIn

More about: ADVENT, CA Technologies, Crucial, Datacom, DataCom, IBM, IBM Australia, ISO, Juniper, Juniper Networks, McAfee, RSA, RSA, The Security Division of EMC, Symantec, Technical Architecture Solutions, Technical Architecture Solutions, Trend Micro, Websense

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the ARN comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: security, virtualisation
ARN Directory | Distributors relevant to this article
ACA Pacific , Anyware Corporation , Aquion , ASI Solutions , Australasian PC Distributors (APCD) , Australian IT Spares , Avnet Technology Solutions , Banksia Software , Dicker Data , Express Data , Express Online , Impact Systems Technology , inTechnology Distribution Pty Ltd , Leader Computers , Lynx Technologies , NewLease , POS POS , Synnex Australia , Topstar Computer International , Westcon Group , Xpress I.T.
ARN Directory | Vendors relevant to this article
CA , IBM , Symantec , Crucial , Trend Micro
rhs_login_lockGet exclusive access to ARN's news, research and invitation only events.
ARN Distributor Directory
ARN Vendor Directory

iAsset is a channel management ecosystem that automates all major aspects of the entire sales,marketing and service process, including data tracking, integrated learning, knowledge management and product lifecycle management.