Burton Group Develops Five Immutable Laws of Virtualization Security
Market Wire, January, 2008
Burton Group, an IT research firm focused on enterprise infrastructure technologies, published a report providing five immutable laws of virtualization security to help IT organizations ensure improved protection of virtual environments.
Virtualized environments are poised to provide significant operational benefits to enterprises, but they are not without their risks. The introduction of a new layer of software -- in the form of the hypervisor -- and the new architectures that provide the benefits must be evaluated from a security perspective to understand the risk and security impact.
In the report, "Attacking and Defending Virtual Environments," senior analyst Pete Lindstrom reports the threat level for virtualization technologies is accelerating quickly as adoption of virtualization grows. Additionally, malicious attackers are realizing that virtual environments are cheaper targets.
With a clear understanding of an organizations specific use cases of virtualization, combined with standard risk principles, Burton Group developed a set of five immutable laws to help IT organizations drive security decisions in virtual environments:
Law 1: All existing OS-level attacks work in the exact same way.
Law 2: The hypervisor attack surface is additive to a system's risk profile.
Law 3: Separating functionality and/or content into virtual machines (VM) will reduce risk.
Law 4: Aggregating functions and resources onto a physical platform will increase risk.
Law 5: A system containing a "trusted" VM on an "untrusted" host has a higher risk level than a system containing a "trusted" host with an "untrusted" VM.
"Burton Group recommends the best way to determine how virtualization impacts security is to determine where and when to apply controls that are sufficient in the environment based on risk tolerance," says Lindstrom. "Ultimately, whether virtualization is a bane or boon for security depends on how the systems are configured, deployed and managed."
More details about the five immutable laws of virtualization on Burton Group's Security and Risk Management Strategies blog at http://srmsblog.burtongroup.com// .
About Burton Group
Since 1990, Burton Group ( www.burtongroup.com ) has provided research and advisory services helping Global 2000 organizations make smart enterprise architecture decisions. Burton Group provides a suite of context-oriented analysis and a proprietary IT Reference Architecture covering security, identity management, application platforms, service-oriented architecture, network and telecom, collaboration, content management, and the data center. Uniquely focused on the need of IT buyers rather than technology providers, 85% of Burton Group's revenue comes from end-user organizations.
Add to Digg Bookmark with del.icio.us Add to Newsvine
Contact: Amie Johnson Email Contact 801-304-8136
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Most Recent Business Articles
- Research and Markets: Top Chinese Information Technology Outsourcing Vendors, Black Book Survey 2009 Results
- Sanofi-aventis Video Q&A : CEO Chris Viehbacher Comments on 2009 Full-Year Earnings
- CSR creates the industry’s first audio processor with Bluetooth connectivity for handsets
- CSR connectivity platform powers the latest Sharp handset
- Samson Oil & Gas Advises on the Gene #1-22H Well Progress
Most Recent Business Publications
Most Popular Business Articles
- 7 tips for effective listening: productive listening does not occur naturally. It requires hard work and practice - Back To Basics - effective listening is a crucial skill for internal auditors
- FHM Features Anna Benson, Baseball's Hottest Wife
- Building a DNA database: the federal government has just enacted two bills related to DNA. The first would drive the collection of DNA from all infants. The second would attempt to prevent the DNA that is collected from being misused
- America's most wanted j-o-b-s - 10 hottest employment opportunities
- Developmental sequence in small groups


