Skip to main content

Posts

Showing posts with the label Compliance

NetWrix's Compliance initiative for Virtual Environments

NetWrix has some cool things going with their Change reporter for both VMware and Microsoft's SCVMM. VMware was launched recently. Change auditing is an important process for controlling the management of your virtual environment, to limit unauthorized changes and errors in VI3 inventory. Erroneous and unauthorized changes usually occur every day in organizations in which many IT professionals manage different aspects of virtual infrastructure. Such changes can cause failures and outages in your virtual infrastructure and significantly contribute to virtual machine sprawl. NetWrix Change Reporter for VMware Infrastructure 3 audits all changes and enforces controlled change management processes across your virtual environment. This freeware tool sends a daily report pointing to every change made to your ESX servers, folders, clusters, resource pools, virtual machines, and their hardware (*), including previous and current ("before" and "after") configuration valu...

Cloud Computing will be all about GRC!

3. Data Regulations: Each jurisdiction around the world has slightly different approaches to the regulation of data privacy and the Australian Law Reform Commission has recently released a report suggesting significant strengthening of Australia's data privacy regime. Therefore it is important that customers understand where their data will ultimately be stored and by whom so that they can ensure compliance with Australian privacy and also record retention regulations. Many SaaS providers work on the basis of centralised infrastructure that is not based in Australia. The customer must ensure that contractually the provider is bound to comply with Australian privacy laws before allowing the data to be exported. The issue is further compounded if the SaaS provider then uses a third party to do the storage of the data. Such is the complexity that EMC announced recently that it is having difficulty choosing a location to build the data centres to run its storage-as-a-service offering...

OpenService announces Risk-Based Security Metrics in InfoCenter 5.1

A quick look at the OpenService Architecture OpenService, a provider of log and IT risk management solutions, has announced a new risk-based security metrics reporting system to help corporations monitor their IT risk trends and determine the effectiveness of their security controls. Available in the new release of its software product, InfoCenter 5.1, this solution was beta tested and first deployed on IBM BladeCenter servers. According to OpenService, InfoCenter 5.1 measures risk automatically by analyzing events reported by security and network devices, operating systems, databases and applications. The risk level of each event is scored as a function of threat, vulnerability, and asset value - an industry standard approach for calculating risk. The company said that the algorithm it developed, called Risk-Weighted Event Scoring and Thresholding (RWEST), scores and correlates events from a wide range of servers, devices and applications and, based on this, supports the visualization...

EU wants Data Centers to comply to CoC

My talk today at a dutch congress, was about security and compliance. Funny thing to see is the bewilderment of the public. This first initial nudge by the EU is a mere reminder that a very resounding governmental interventionism is definitely in the offing. Compliance will come in many ways: There will be strong focus on an organization's CSER policy, one may be asked to demonstrate it periodically GRC (Governance, Risk and Compliance) will play major role in every strategy and organizations will be tested and funded (under-funded) accordingly A snippet on the expected compliance w.r.t Data Management and Security The EU is asking data centre owners and operators to "voluntarily" sign up to a Code of Conduct (CoC) which will include oversight of their energy efficiency in what could be green regulation through the back door. The European Commission has issued its Code of Conduct for Data Centres Energy Efficiency and invited data centre owners and operators to sign u...

VMware attempts to clarify security confusion as PCI DSS 1.2 leaves VI out

Alex reporting: The company has also launched the VMware Compliance Center, a website dedicated to educating merchants and auditors about compliance in a virtualized environments, and the resource includes links to relevant white papers and webcasts. With its entrance into PCI SSC, VMware hopes to address confusion about whether virtual environments comply with existing standards for data security. "Right now, from an audit perspective, there is confusion around if someone wants to use virtualization, if it can be used in a PCI-compliant environment," said Bill Hau, the vice president of Foundstone Professional Services, a division of security vendor McAfee. Bringing PCI DSS into the virtual world Founded by a core group of credit card merchants, including American Express, Discover, JCB International, MasterCard, and Visa, PCI SSC developed the PCI Data Security Standard (PCI DSS), which is a set of guidelines that participating merchants must follow to safeguard credit card...

VMware launches "Compliance Center"!

As regulatory compliance expands, more and more of your virtual environment will become subject to security and compliance standards, such as PCI DSS, HIPAA and SOX (GLBA). With the proper tools, achieving and demonstrating compliance on VMware Infrastructure is not only possible, but can often become easier than a non-virtual environment. Assess the Management Control Features in a Virtual Platform Having a secure foundation is the first step. As security threats grow and evolve, your security environment will need to be flexible and adaptable. Security standards require enterprise-grade management features in order to provide the necessary controls for achieving and demonstrating compliance. The following describes the management features that a virtual computing platform should have in order to be compliance-ready. Start by Looking at Authentication and Authorization Capabilities Security management starts with authentication and authorization. All virtual platform interf...

Regulated Cloud Computing: Traffic Monitoring Tool is here

If this is no proof of the "triple convergence" (Personal, Business and IT) then nothing is. Data Theft and misuse of data, whether its pronography or merely stealing company data, it will and should all be monitored. Whether you like it or not, regulatory compliance is coming at you in a big way. A look at their slide: That actual knowledge could be handed to the Internet companies by technologies like the one proposed by the Australian company, Brilliant Digital Entertainment Ltd. Known as CopyRouter, the software would let ISPs compare computer files — movies, photographs and documents — against those lists. Banned files would be blocked, and the requestor would receive a substitute file provided by law enforcement, such as a warning message: "The material you have attempted to access has been identified as child pornography." The attempt to send or receive the file could then be reported to law enforcement, along with the Internet Protocol address of the request...

Cloud Computing Debate heats up among policy makers

I am pleased that all these issues are being addressed right from the start. Finally we'll have discussions that will lead to a well regulated adoption that will be secure and compliant while still being open and free. Despite the growing number of people using cloud services such as hosted e-mail and online photo storage, many consumers don't understand the privacy and security implications, said Ari Schwartz, vice president and chief operating officer of the Center for Democracy and Technology, an advocacy group focused on online privacy and civil rights. So far, U.S. courts have generally ruled that private data stored in the cloud doesn't enjoy the same level of protection from law enforcement searches that data stored on a personal computer does, he said. "Consumers expect their information will be treated the same on the cloud as it is if it were stored at home on their own computers," Schwartz said. Forty-nine percent of U.S. residents who use cloud co...

Security & Compliance: Accountability a big issues in Virtual Infrastructure

No you don't have to panic here. you have all the staff in place to take over these replacing responsibilities (note, I didn't say additional since they will eventually have to let go of a lot of old habits and practices, it that offers some relief). Your Security staff, SOX team or whatever you have in place and/or other folks are the ones who must define standards and frameworks that are compliant to the typical security audit scenarios. Obviously this can also be a means to bring a lot of folks from other domains to participate in the whole "virtualization party" (as it is often, sarcastically mentioned by the guys who have no idea who these "virtualization team" is) actively. Security is undoubtedly a very improtant arena, in the older world, it just didn't take off. I still remember when I was pushing , that was 7 years back, some auditing practices that could give us more granular control on operational FGAC on the databases, people just looked at ...

StoneFly Unveils New Server Virtualization and Encryption Capabilities

At the LinuxWorld Conference & Expo, August 4-7 at San Francisco's Moscone Center, StoneFly, Inc., a leading supplier of integrated IP storage area network (SAN) systems and a wholly owned subsidiary of Dynamic Network Factory, Inc. (DNF), will unveil enhanced server virtualization capabilities across its entire IP SAN line through certification with both the Citrix/Xen and VMware platforms. StoneFly is exhibiting the new capabilities at the event in booth #1315. In addition, the company will debut its new SAN-based encryption capabilities for the StoneFly Integrated Storage Concentrator (ISC) line of high-availability IP SANs. Lastly, StoneFly will demonstrate, for the first time, its robust new StoneFusion 6.1 intelligent network storage platform, which is now being offered as a standard, integrated component of all StoneFly IP SANs to deliver block-level provisioning and centralized storage management, control and monitoring of logical storage volumes. ...

Security, Virtualization and Global Floatability: Implications of data theft; ex-HP exec gets 10 yrs jail!

I have been talking about virtualization security for quite a while. My last speech in EMEA, Belgium 2008 specifically, at the Open Source Virtualization Conference , I mentioned this, see this picture and think about it. Think about it as a security expert, think about it as a CIO, think about it as a company lawyer and think about it as an employee! Just give yourself a moment, look at this picture: Now tell me what you see in it? Well lets ponder about it once again. My Real-Time consultations and observations across the globe tell me one thing. just like the iRobot movie line from the robots: " You will comply!" or even better yet: "Wanna spend you life in jail?". You will have to deal with several compliances when the IT and Business domains converge. I have said it on several occasions. The consolidation is bound to continue. It will go on this time till we have reached an absolute state of meshed or mashup domains. There will be several disorders and there w...

Virtualization maybe great but I/O, compliance and security concerns still remain!

Xsigo takes an interesting approach in addressing the I/O concerns. The solution is to virtualize server I/O. That is, turn normally fixed and static I/O channels, host bus adapters, and network interface cards into more dynamic resources whose capacity can expand and contract based on virtual server needs. If I/O virtualization could be achieved, it would resolve a persistent problem server administrators have as they stack virtualized applications on the same hardware. Until virtualized I/O becomes commonplace, applications with heavy or fluctuating I/O demands aren't being virtualized, lest they end up causing I/O backups. Two early solutions have emerged and more are sure to follow. Startup Xsigo off-loads I/O traffic to an attached appliance that virtualizes it (see diagram, p. 20). The approach requires replacing standard HBAs and NICs on the server with Xsigo custom cards and investing in the Xsigo appliance. Pricing starts at $30,000. Xsigo's appliance can generate up t...

Identity Management Software Market to reach $4.9 Bn by 2012

Proliferation of access levels and number of highly sensitive transactions has brought to fore the importance of identity management in the corporate world. Regulatory requirements are one of the critical factors providing impetus to market growth. Laws such as GLBA, HIPAA, California SB 1386, Sarbanes-Oxley, the USA Patriot Act, and the EU Data Protection Directive require businesses to establish authentic users by employing realistic methods and monitor access to resources, while also protecting user privacy. To meet growing demand, vendors are focusing on end-to-end identity management products to enable businesses to manage identity security issues. Integration of meta-directories and password management into provisioning and tighter integration between Web single sign-on and provisioning solutions are some of the key product trends. Federated identity management (http://www.strategyr.com/Identity_Management_Software_Market_Report.asp) is also fast gaining market acceptance. United...

Compliance challenges while virtualizing

Chris @ Fortisphere writes: Here are five challenging aspects of IT compliance when dealing with virtualisation: Discovery and inventory: You can't measure what you can't see (or for that matter, don't even know exists). Determining which virtual machines (VMs) are active, which are abandoned or dormant and what data they are accessing is a fundamental part of defining your scope of compliance and applying the appropriate IT controls. Perhaps of a greater concern is how organisations cope with unapproved or rogue VMs. Chain of custody: Can you provide an audit trail for critical VMs as they move from development to testing to production? Are only approved changes occurring and are they made by the appropriate personnel? Due to the dynamic and mobile nature of virtualisation, keeping track of where the VMs are, who touched them and what changed is key for audit documentation and a true lifesaver in incident response scenarios. Separation of critical assets (especially in a ...