Find White Papers
Home
About Us
List Your Papers
    
> Tripwire > Is Virtualization Under Control?

Is Virtualization Under Control?

White Paper Published By: Tripwire

Tripwire surveyed IT professionals to learn how virtualization is expanding and if security, change controls and compliance requirements are keeping pace. Read this white paper to learn more about the state of virtualization today and why most of the respondents agree that a dedicated configuration tool is needed and are in the process of evaluating or planning to acquire such a tool.



Tags : 
virtual, virtualization, tripwire, configuration, change managemement, change management, server virtualization, configuration management

Tripwire
Published:  Jul 25, 2008
Type:  White Paper
Length:  10 pages

WHITEpaper
Is Virtualization Under Control?
Current Opinions on Security and Controls for Virtual Servers in Production Environments
page 2 Executive Overview
page 3 Virtualization in Production
page 4 Security and Controls
page 6 Organizational Responsibility
page 8 Inhibitors and Enablers
page 9 Summary
page 10 About the Survey
page 10 About Tripwire
İİ22000088 TTrriippwwiirree,, IInncc.. TTrriippwwiirree iiss aa rreeggiisstteerreedd ttrraaddeemmaarrkk ooff TTrriippwwiirree,, IInncc.. AAllll ootthheerr pprroodduucctt aanndd ccoommppaannyy nnaammeess aarree pprrooppeerrttyy ooff tthheeiirr rreessppeeccttiivvee oowwnneerrss.. AAllll rriigghhttss rreesseerrvveedd..WHITE?PAPERIs Virtualization Under Control?
Executive OverviewTripwire recently surveyed enterprise IT professionals to assess how vigorously virtualization is expanding within production server environments and to gauge if security, change controls and compliance require-ments are keeping pace. Virtualization has clearly gained a lasting foothold, and the strength of IT process controls on virtual servers is reported to be on par with those implemented in the physical realm. However, opinions on who is responsible for ensuring that security and controls are instituted across virtual infrastruc-ture vary between functional groups.. Virtualization in Production: More than 90% of those interviewed said that virtualized servers are now deployed in their production environments and run a wide variety of applications. For three out of four respondents, up to half of their production servers are now virtualized.. Security & Controls: Compared to physical servers, the strength of controls for virtualized servers are perceived as equivalent, if not even stronger. More than 80% of respondents said their change management and compliance controls are no different. A total of 26% felt security controls for virtualized servers are actually more stringent. . Organizational Responsibility: A "tug of war" may be underway over who is accountable for security and controls for virtual servers. Just half of those surveyed felt that ensuring security, change control, and compliance for virtual servers is the responsibility of system administrators and their management. On the other hand, 37% of those associated with the Security group claim responsibility for security controls.
A serious issue awaits for some organizations deploying virtual servers in production environments. Eight out of 10 respondents said that the greatest factor limiting the expansion of server virtualization is a lack of time, staff, and/or skills. The majority also agreed that security risks for virtual servers are the result of mis-configuration, not inherent weaknesses of virtualization technology. If an increasingly overworked IT staff is more likely to make mistakes, and configuration errors are the cause of security exposures in virtual servers, then IT management must consider how they can mitigate this risk.
As more of the production workload becomes virtualized and those managing virtual servers continue to be overwhelmed, it is apparent that automated configuration control must play a larger role to ensure appropri-ate server configuration and adequate security. A majority of 69% agreed that a dedicated configuration tool is needed to ensure proper configuration of virtualized servers, and two-thirds of these respondents are in the process of evaluating or planning to acquire such a tool over the next 12 months.
Page 2WHITE?PAPERIs Virtualization Under Control?
Virtualization in ProductionVirtualization is being broadly adopted within enterprise IT infrastructure for many reasons, and industry analysts and journalists have explored the topic in detail. According to a comprehensive report on virtualization trends and forecasts conducted by Enterprise Management Associates (EMA) released in April 20081, server consolidation and improved hardware utilization tops the list of most organizations, as these drivers successfully translate to reduced hardware costs and floor space requirements. Other critical benefits include reducing downtime, enabling more effective disaster recovery and business continuity, and ensuring better achievement of service level agreements.
Test and Development, according to the EMA study, remains the ... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search