Rick Holland serves Security & Risk Professionals. See the full Analyst bio.
Visit Forrester.com to learn how we make Security & Risk Professionals successful every day.
Virtualization Security, Better Late Than Never
Posted by Rick Holland on January 17, 2012
- 290 Recommendations
- 0 comments
I am excited to announce my latest research, The CISO's Guide To Virtualization Security. This is the first report in a new series focusing on securing virtual environments. The reduced costs and flexibility of virtualization have led to widespread adoption of the technology. Despite this adoption, security and risk professionals haven't given their virtual environments the attention that is required. Our research interviews revealed several themes:
- Business as usual is the status quo. IT departments rely upon traditional security solutions (end point and network security) to secure their virtual environments. Depending on the network architecture, virtualization can create blind spots in your network leaving you blind to intra-virtual-machine (VM) communication.
- Many security pros aren't aware of the virtualization aware solutions available on the market. One CISO we spoke with wasn't aware that his organization's current antivirus vendor offered a virtualization aware solution. This isn't necessarily surprising; many of the virtualization aware security solutions are relatively new to the market. Virtualization aware solutions afford us the ability to have potentially greater visibility into workloads than we might have in our traditional physical environment.
- Many security pros have a general discomfort with virtualization. Security pros, especially CISOs and other security leaders who have risen up the technical ranks, aren't as confident in their virtualization knowledge as they would like to be. This is particularly the case when we compare virtualization with more mature security areas, such as network security.
- As organizations virtualize more and more servers, the "low hanging fruit" servers have been virtualized and enterprises are now moving on to mission critical workloads. Virtualizing these workloads brings up security and compliance concerns that can slow virtualization adoption.
As organizations seek to increase virtual server utilization and navigate a complex compliance landscape, it is critical that Security & Risk Professionals take a fresh look into the security of your virtual environments. If you haven't done this, now is the time. As Mark Twain said, "better late than never." You should strive for virtual security that is at least on par with your traditional security and look for opportunities to implement better security and visibility within your virtual environment. In this report, we discuss the challenges and risks associated with virtual environments, and make recommendations on how to get into the virtualization security game.
Please join me for a webcast discussing this report on Thursday, February 23 from 1:00 p.m.-2:00 p.m. Eastern time.
In the future, we will be writing a detailed report on Zero Trust within virtual environments including guidance for virtual desktop deployments. If you have any questions or comments please let me know.
search forrester's blogs
Secure the digital business future.
Attend Forrester’s Forum for Security & Risk Professionals EMEA, June 10-11, London UK
Analyst Blogs
- Andras Cser (30)
- Andrew Rose (17)
- Chris McClean (54)
- Christopher Sherman (1)
- Edward Ferrara (19)
- Eve Maler (19)
- Heidi Shey (9)
- John Kindervag (28)
- Khalid Kark (13)
- Laura Koetzle (2)
- Nick Hayes (5)
- Rick Holland (20)
- Stephanie Balaouras (50)
Top Categories
- Incident Response (8)
- data security (4)
- cybersecurity (3)
- Forrester's Security Maturity Model (3)
- malware (3)
- NAV (3)
- threat intelligence (3)
- client security (2)
- cyber threat intelligence (2)
- data breach (2)
- See all
Archives
- April 2013 (2)
- February 2013 (3)
- December 2012 (2)
- November 2012 (1)
- September 2012 (1)
- August 2012 (1)
- May 2012 (3)
- March 2012 (1)
- February 2012 (1)
- January 2012 (2)
- November 2011 (2)
- October 2011 (1)