There have been several interesting posts in the blogosphere about virtualization security and how to measure it. Specifically, the discussions are really about the size of the hypervisor footprint or about the size of patches. But hypervisor footprints from a security perspective are neither of these. The concern when dealing with hypervisor security is about Risk not about the size of the hypervisor or the size of a patch it is purely about the Risks associated with the hypervisor in terms if confidentiality, availability, and integrity.

Veeam has posted a blog of their own trying to explain why they are no longer selling Veeam Backup 3.x for the Free version of VMware ESXi. It is perfectly understandable that Veeam would comply with VMware’s requests in this matter as Veeam as a company depends upon their relationship with VMware to further their own business aims. In other words, Veeam has done nothing that could be considered wrong. However, VMware making the request in the first place should be a major concern to current and future vendors of VMware products.