Virtualization Security

Virtualization Security focuses upon end-to-end security, integrity, auditability, and regulatory compliance for virtualization and clouds.

Most Recently added Virtualization Security Resources: (See More...)

Teenager’s View of Cloud Security: Expectations of Privacy

June 1, 2012
By
VirtualizationSecurity

The 5/3 Virtualization Security Podcast had a very special guest, a teenager. This surprise guest told us about how she and her friends use their smartphones and cloud services such as FaceBook, Twitter, SMS, etc. For the panelist, it gave us a new look at our existing problems; expanding our viewpoint for end-user computing security,…

Read more »

End User Computing: Protecting Data From the Device

May 25, 2012
By
siri

Some of us have multiple cloud endpoints in the form of mobile devices all trying to access our personal and corporate data to do our daily jobs. These incredibly useful devices (smartphones, tablets, etc.) are now a part of our organizations life. So how do we protect our data from them. IBM recently took a…

Read more »

Filling the Gaps: Focus on Application Security

May 24, 2012
By
VirtualizationSecurity

Symantec and others are providing more products that fill the gaps in current End-to-End Hybrid Cloud Security. These solutions range to improved log analysis through multi-layer security for critical systems. If these solutions are rolled out would we finally have secure environments? Would we be approaching the dream of secure multi-tenancy? But first what are…

Read more »

Multi-Tenancy: Who is the Tenant?

May 15, 2012
By
VirtualizationSecurity

There seems to be a myriad of definitions of who is a tenant when it comes to secure multi-tenancy. This debate has occurred not only within The Virtualization Practice as well as at recent Interop and Symantec Vision conferences I attended. So who really is the tenant within a multi-tenant environment? It appears multiple definitions…

Read more »

Offering Cloud Services: Why is it so Limited?

May 8, 2012
By
CloudComputing

There are many SaaS and Security SaaS cloud services out there, but they all lack one thing: full visibility. Why do these cloud offerings limit the ability to perform compliance auditing, forensics, and basic auditing against an organizations data retention, protection, and other necessary policies? Why not just grant the "right to audit", or better…

Read more »

Will access to VMware’s source code change the hypervisor threat landscape?

May 1, 2012
By
VMware100x30

Many of the virtualization security people I have talked to are waiting patiently for the next drop of leaked VMware hypervisor code. But the real question in many a mind is whether or not this changes the the threat landscape and raises the risk unacceptably. So let's look at the current hypervisor threat landscape within…

Read more »

Tenant and Multi-Tenant Security: Its all about Scope

April 11, 2012
By
CloudComputing

While at InfoSec World 2012's summit on Cloud and Virtualization Security, the first talk was on Securing your data. The second was on penetration testing to ensure that data was secure. In essence it has always been about the data but there is a huge difference between what a tenant can do and what the…

Read more »

Application Security using Secure Cloud Storage

April 3, 2012
By
CloudComputing

VMware's Project Octopus and others like ownCloud and Oxygen Cloud have stirred some interesting ideas about Application Security. Those applications that make use of SSL, nearly every web application, can make use of secure data storage for certificate verification means. What makes SSL MiTM attacks possible, is mostly related to poor certificate management. If there…

Read more »

Improving Virtualization and Cloud Management Security with Symantec CSP

March 30, 2012
By
VirtualizationSecurity

The 3/22 Virtualization Security Podcast brought to light the capabilities of Symantec Critical System Protection (CSP) software. This software successfully implements a manageable version of mandatory access control policies based on role-based and multi-level security functionality within the virtual environment. More specifically on those systems that are critical to the well being and health of…

Read more »

Featured Solutions