Home > Ask the Security Channel Experts > Selling Security Technology and Services with Christofer Hoff Questions & Answers > Where do I start in discussing virtual security with my customers?
Ask The Security Channel Expert: Questions & Answers
EMAIL THIS

Where do I start in discussing virtual security with my customers?

Christofer Hoff EXPERT RESPONSE FROM: Christofer Hoff

Pose a Question
Other Security Channel Categories
Meet all Security Channel Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 14 April 2008
Virtualization has profound architectural and security ramifications. Where do I start in discussing virtual security with my customers?

>
EXPERT RESPONSE
Virtualization offers fantastic solutions to many of the economic and technology-driven problems that enterprises and small business alike share today. The thought of consolidating expensive and underutilized computing and storage platforms to reduce footprint, power and cooling costs, and improve resilience is tantalizing to any CIO or CFO.

The challenge arises when the network and security teams discover that they've lost a good deal of the security visibility and operational control they once had, since both the network and hosts are virtualized on a single platform operated by the server administrators. This makes compliance, competencies and separation of duties trickier.

To ensure virtual security, work with your customers to address policies, procedures and responsibilities across server administration, network and security teams before you start deployments. This will limit the operational impact of virtualization.

Further, virtualization adds complexity that extends beyond management and provisioning, and changes the attack surface of your server and workstation deployments. Until security technology catches up with the virtualization vendors and tools become better integrated with the underlying virtualization infrastructure, recommend the following basic virtual security guidance to your customers:

  • Follow the virtualization vendor's virtualization security hardening recommendations, paying strict attention to management and security settings.
  • Harden virtual hosts by using the same processes, procedures and technologies you would employ on a physical server.
  • Isolate virtual hosts in physically or logically segmented networks to prevent attackers from leapfrogging to traditionally secured physical hosts until you are comfortable with the impact virtualization has on security and networking.
  • Group virtual machines that interact with one another on the same host using properly allocated virtual switch(es) to optimize performance and security.
  • Perform a risk assessment that demonstrates clearly that the business understands what consolidating critical service infrastructure means to service levels, availability, business continuity planning and disaster recovery.
  • Take into consideration that licensing models for security applications are still evolving in the virtualized world.

The best discussion to have with clients about virtualization is how to balance the business benefits with the potential operational, architectural and security changes, and be honest about how that will impact the organization.


Sound Off! -   Be the first to post a message to Sound Off!


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Selling Security Technology and Services with Christofer Hoff
Can enterprises place too much emphasis on security regulatory compliance?
What are the best data leakage prevention strategies for my clients?
How will the planned changes in PCI-DSS affect the channel?
What is the future of antivirus or antimalware software?
What accounts for the trend toward SMB security?
Why is it important to use security metrics with my clients?
How can service providers help with IT risk management?
What should I know about green security?
How do I help clients with end-user security policies?
How do I determine the right number of security vendor partners?

SMB Security
What accounts for the trend toward SMB security?
Check up on IT security services for your clients
How to take advantage of the SMB opportunity
What event management tools are available for SMBs?
The rise of midmarket security
Top SMB security tips for resellers and service providers
Encryption can save data security breaches
SMB security projects for resellers
IBM to sell managed security to SMBs -- through the channel
Email security options for SMBs

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts