Whitepaper: Virtual Machine Security Guidelines

analysis
Sep 9, 20072 mins

Virtualization security is always a hot topic of discussion. And now the Center for Internet Security (CIS) is joining in that discussion with its latest whitepaper titled "Virtual Machine Security Guidelines - Version 1.0". For those not familiar with CIS, they are an independent body that provides benchmarks, scoring tools, software, data, information, suggestions and ideas as a public service to Internet user

Virtualization security is always a hot topic of discussion. And now the Center for Internet Security (CIS) is joining in that discussion with its latest whitepaper titled “Virtual Machine Security Guidelines – Version 1.0”.

For those not familiar with CIS, they are an independent body that provides benchmarks, scoring tools, software, data, information, suggestions and ideas as a public service to Internet users worldwide. Their recommendations are typically the result of a consensus-building process that involves many security experts and are generally generic in nature.

The 30 page whitepaper addresses security concerns that apply to virtual machine technologies. Their recommendations are considered to be vendor neutral and are based on a variety of public sources and contains input from members of the Center for Internet Security.

While the document focuses on issues that are unique to virtual machine deployments, it does not cover all of the steps that are needed to harden the individual operating systems. Other documents from the CIS provide the necessary guidance to secure other aspects of a computing infrastructure.

The next CIS whitepaper will be the addendum for VMware ESX Server. That document will cover specific steps needed to apply the general concepts discussed in this document to an installation of VMware ESX Server.

You can download and read the entire whitepaper, here.