* Virtually secure
endif; ?>By all accounts, virtualization technology is fast moving beyond its traditional test and development strongholds and into production environments. While most IT professionals I talk to say really critical and power-hungry business applications such as databases likely won’t move into the virtual world soon, many other really important workloads are.
So I’m wondering how security plays into the whole planning process once you take a bunch of applications that have been running on separate physical servers – most likely with separate firewalls, intrusion protection and other security features – and throw them into virtual machines on a single physical system?
My colleague, Network World Senior Editor Ellen Messmer took a close look at the issue recently. You can read her report here. She makes a bunch of good observations in the piece perhaps most importantly that security is really an afterthought these days when it comes to virtual environments.
Analysts say that few security vendors – among them Blue Lane Technologies, Reflex Security and StillSecure – are addressing the issue and rolling out software-based security products designed to work with virtualization technology.
It seems that most companies virtualizing x86 servers are using VLANs to secure them, but what happens as their virtual environments grow? At that point, most will need security capabilities built into the virtualization software so that each virtual machine is protected individually.
Blue Lane Technologies, for example, earlier this year introduced Virtual Shield, which embeds security capabilities at the hypervisor level in VMware Infrastructure 3. To be fair, VMware offers its own security capabilities, such as the ability to encrypt a virtual machine, but are they enough in business critical environments?
In a recent report, Gartner analysts warn that companies that aren’t careful with their virtual architectures may end up overlooking important security concerns. Andreas Antonopoulos, author of Network World’s Security in Practice newsletter, also says that security issues are likely to rear their ugly heads in virtual environments if end users aren’t vigilant.
At the same time, there is work underway to put standards in place when it comes to virtualized servers and security. What are your thoughts? How are you approaching security as you expand your virtual environments? Let me know.




