nCircle.com >> nCircle Blog >> Sync

« The Obama Administration’s Cyberspace Policy Review Turns Up a Dud | Main | RSA 2009 Recap »

RSA Virtualization Security Panel Review

Putting Simon Crosby and Chris Hoff on the same panel to discuss virtualization security is a recipe for a good lively discussion. At the end of the panel, the audience was not disappointed. In addition to Crosby and Hoff, the panel also included Michael Berman of Catbird and Stephen Herrod of VMware.

The discussion started with some hi jinx by Crosby and Hoff. Crosby handed out gifts to the panelists that included a broken toy sword and a ball and chain. Hoff gave out cigars, one notably much smaller for his nemesis, Mr. Crosby. Despite Chris Hoff's sometimes-flamboyant style, he initially came out mild mannered and on an even keel. His moderate, centrist and thoughtful approach lasted throughout the discussion. Conversely, Simon Crosby of Citrix and huge proponent of Xen spent most of his time trying to put VMWare into a corner. Crosby touted Xen as the most secure hypervisor system because of its open nature and its continuous real life testing because of it's use as the foundation of Amazon's EC2 offering.

Despite the moderator's attempts to encourage the panel to discuss real world security implications of virtualization, the topics kept going back to the implementation and security of VMware products like vShield. In the final moments of the session, the panelists did finally provide a few recommendations worthy of implementing today. One of these nuggets was that insight included most of the security basics necessary for all systems, virtualized or not. Examples of these basics included using configuration guidelines, creating operational plans that include security and risk considerations and building architectures that consider the security implications of the entire virtualization life cycle.

Overall, the virtualizations security panel was entertaining and insightful.


TrackBack

TrackBack URL for this entry:
http://blog.ncircle.com/cgi-bin/mt-tb.cgi/340

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Verification (needed to reduce spam):

Bio

Blog: Sync
Author: Andrew Storms

As nCircle's Director of Security Operations, Andrew Storms is responsible for the definition and enforcement of the company's security compliance programs as well as overseeing day-to-day operations for the Information Technology department.
Andrews' commentary on IT security issues has appeared in CNBC, Forbes and The New York Times, as well as many other publications. He is a Certified Information Systems Security Professional (CISSP) and a member of FBI InfraGard.

About

This page contains a single entry from the blog posted on April 23, 2009 3:31 PM.

The previous post in this blog was The Obama Administration’s Cyberspace Policy Review Turns Up a Dud.

The next post in this blog is RSA 2009 Recap.

Many more can be found on the main index page or by looking through the archives.