Shift to virtualized environments shaking up security practices

By Ellen Messmer, Network World |  Virtualization Add a new comment

The move to almost fully virtualized computing environments is driving a fresh approach to security in the enterprise, according to information technology security managers applying controls for VMware and Microsoft Hyper-V.

"We're very close to being 100% virtualized," says Gurusimran Khalsa, systems group supervisor in the state of New Mexico's human services department. That organization's servers are based on VMware's vSphere, and a virtual desktop project is being started, too. The agency's 170 server-based virtual machines (VMs) run in its local data center, with a range of Web applications, multi-tiered IT systems, file servers, domain servers, SharePoint and SQL servers.

ANALYSIS: New security demands arising for virtualization, cloud security

Because of a security breach that occurred a few years ago -- the loss of sensitive data was considered so serious that several IT staff were laid off -- the agency in Santa Fe has sought to keep a tight rein, requiring two-factor authentication to get into servers and introducing "air gaps" to protect some sensitive data. But at the time, while the benefits of virtualization, such as server consolidation, were being introduced, it wasn't fully understood how this transformation would impact security, says Khalsa.

Increasingly, there was concern among security and compliance officers that if VMware's vCenter management console were compromised, the game would be over. "It's the central point of access to vCenter that manages our production environment," says Khalsa.

To beef up controls there, the agency decided to install the HyTrust virtual appliance, which intercepts administrative requests to the virtual infrastructure to determine which requests are in line with the organization's policies. "We have a couple of vSphere admins at a higher level of access," says Khalsa. HyTrust can be set up to ensure only certain workloads are permitted to boot up in specific hosts or clusters, and it can label virtual objects and apply policies to them.

The agency also began using the Juniper vGW Series firewall, which is based on its acquisition of startup Altor Networks last December. "The firewall is positioned between the VM and vSwitch," says Khalsa. "It's set up similarly to a regular firewall, with least privilege."

While the agency still uses VLANS to cordon off some servers, the Juniper virtual gateway firewall provides far more granular controls, and has the ability to do introspection on the VMs to see what's installed and set rules based on that, says Khalsa.

Other agencies and businesses say they also needed to look at new approaches for security in their virtualized environments.

"We're about 80% virtualized," says Rick Olejnik, chief information security officer at Brookfield, Wis.-based law firm Rausch, Sturm, Israel, Enerson & Hornik (RSIEH), which specializes in debt collection and has offices in 13 states.

One of the main concerns the law firm had was securing credit-card data in its VMware ESX server environment, even though the credit card numbers are defunct. About a year or so ago the banks and financial institutions which are RSIEH's clientele made it clear that although these are no longer active card numbers, they still need to be protected according to the Payment Card Industry rules.

That meant encrypting them. Ojenik said that led to the decision about eight months ago to deploy the Vormetric appliance for encryption key management along with encryption software on ESX servers to encrypt PCI data at rest, while the agent software works to un-encrypt the data to allow the application called Collection Master to access and process information.

"It's happening at the kernel level and there have been no performance issues at all," says Olejnik. But besides adding encryption to the virtualized computing environment, another security control at the law firm depends on using the Palo Alto Networks application-layer firewall to partition off VMs. "This allows us to do the segmentation required on our internal network," says Olejnik.


Originally published on Network World |  Click here to read the original story.

ITworld LIVE

VirtualizationWhite Papers & Webcasts

White Paper

vRanger Helps Cut Replication Time by Almost 70%

There's a reason why more than 38,000 customers trust vRanger to protect their critical virtual data! In this Quest Software case study, see how vRanger helped Cornerstone Bancshares, Inc. cut replication time from days to minutes - and how this translated to real time and money savings.

White Paper

ESG: Product Brief: Quest vRanger 5.3 brings enterprise-class VMware protection to SMB's

Free paper: how virtualization impacts SMBs, and strategies for enterprise-class VMware protection

White Paper

Converged Storage: Utility Storage - The Ideal Platform for Virtual and Cloud Computing

Server virtualization has transformed corporate IT -- companies have enjoyed major cost savings and have gained flexibility and efficiency. But this has also led to a proliferation of virtual machines and servers that threaten to overwhelm data movement and storage technologies. In this IDG Tech Dossier, learn how utility storage makes for massive consolidation, flexibility and scalability, so IT departments can reduce storage infrastructure and lower costs while improving their ability to respond to fast-changing needs of business units.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

White Paper

Virtualizing the Client - The HP Way

HP VirtualSystem delivers best-in-class virtualization, with integrated software, services, infrastructure, and management - all delivered as one proven solution.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Webcast On Demand

Making Information Matter

Join us in the upcoming Hitachi virtual Forum on Wednesday, June 6th, at 8:30am PT / 11:30am ET and gain meaningful insights on how to maximize efficiency and reduce expenses. At the virtual forum you will learn about key solution strategies in our featured live video sessions from top leaders at Hitachi, like Miki Sandorfi, Chief Strategy Officer and industry experts, such as Ben Woo, VP WW Storage Systems at IDC.

Sponsor: Hitachi

See more White Papers | Webcasts

Ask a question

Ask a Question