Most Popular Stories
- Q&A: Disaster recovery when your business sits on the San Andreas Fault
- Content Marketing could be supplanting the traditional corporate blog
- Enterprise architecture at Chubb Insurance
- CFO has a role to play in ERP rollouts
- Content is the new gold
- Help desks get help at Peugeot, De Beers and University of Georgia
- A 'mobile help desk' in every pocket, from Salesforce.com
- Apple co-founder Wozniak sings Android's praises
- Four ways to better manage IT sales calls
- Section 508 web accessibility rule to change
- Survey finds many users blow by SharePoint security
- How hackers can eavesdrop on prevalent videoconferencing systems
Events
- Northwestern University Master's in Information Systems
- CIO Healthcare Summit
March 11-14 — Scottsdale, AZ - CIO Summit
March 18- 21 — Miami, FL - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Whitepaper: Mobile Device Management Buyer's Guide: An Insider's View of the Market
- 5 Ways to Reduce Enterprise Mobililty Costs with Wireless Telecom Expense Management
- The Top 4 Reasons Your Telecom Expense Management Provider Shouldn't Manage Your Wireless
- The E-discovery Toolbox: What you should look for in a unified e-discovery solution
- Making Change Stick
IBM security expert: X86 virtualization not ready for regulated, mission-critical apps
In a session on virtualization held at Interop Las Vegas this week, IBM security expert Joshua Corman argued that X86 virtualization in not ready for highly regulated, mission-critical applications. The problem is that virtualization opens up new attack surfaces, as well as presents additional operational and availability risks.
In addition, the presence of advanced features--such as live migration of virtual machines--also increases the complexity. Besides the possibility of man-in-the-middle attacks designed to intercept unencrypted data when virtual machines are in transit, another pertinent question to ask is whether a virtual machine moved to a less secure machine.
Indeed, virtualization makes it difficult to meet regulatory requirements such as the PCI DSS. Corman, who is the principal security strategist for IBM's Internet Security Systems division, said, "If you have a choice, I highly recommend you don't adopt virtualization for any regulated project. If you're going to make mistakes, it's better to do so on less critical systems."
Ironically, though, Corman noted how obsession with compliance results in people giving up on risk management. He does offers some advice for organizations working with virtualization. For one, only Type 1, or bare-metal hypervisors should be used for production applications. Also, production applications should be separated from those used for testing or development.
For more on this story:
- check out this article at Network World
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




