All the latest UK technology news, reviews and analysis

Gartner warns on virtualisation security lapses

by Robert Jaques

04 Apr 2007

Be the first to comment

  • Tweet this

Companies that rush to deploy virtualisation software risk undermining their IT security, Gartner warned today.

The analyst firm noted that virtualisation software that can simultaneously run multiple operating systems on one physical server or desktop, regardless of the specific underlying architecture, has significant potential benefits.

However, Gartner went on to warn that a virtualised privileged layer of software that becomes compromised places all consolidated workloads at risk.

"Virtualisation, as with any emerging technology, will be the target of new security threats," said Neil MacDonald, vice president and Gartner fellow.

"Many organisations mistakenly assume that their approach for securing virtual machines will be the same as securing any operating system, and thus plan to apply their existing configuration guidelines, standards and tools.

"While this is a start, simply applying the technologies and best practices for securing physical servers will not provide sufficient protection for virtual machines."

MacDonald added that, because of the rush to adopt virtualisation for server consolidation, many security issues are overlooked and best practices are not applied.

As a result, 60 per cent of production virtual machines will be less secure than their physical counterparts through to 2009, Gartner predicts.

Gartner advised that the process of securing virtual machines must start before they are deployed, and ideally before vendors and products are selected so that security and "securability" can be factored into the evaluation and selection process.

During this process, organisations must consider these security issues in virtualised environments.

"Organisations need to pressure security and virtualisation vendors to plug the major security gaps," said MacDonald.

"Existing virtualisation solutions address some of the gaps, but not all. It will take several years for the tools and vendors to evolve, and for organisations to mature their processes and staff skills.

"Knowledge of the security risks, and the costs to address them, must be factored into the cost-benefit discussion of virtualisation.

"If these added costs are avoided, the risk of not making the necessary security investments must be accepted by the decision maker in the move to virtualisation."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

29%

1%

12%

58%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

PHP Software Developers/Programmers- Automated Trading - London

PHP Software Developers/Programmers- Automated Trading...

1st Level Application Support - Southampton, Hampshire - £20K

1st Level Application Support required to join a leading...

Helpdesk Adviser; Service desk Analyst; Northeast’s; £Neg on Experienc

Helpdesk adviser required for a major organisation in...

.NET Developer

.NET Developer is needed for a financial services...

To send to more than one email address, simply separate each address with a comma.