The i-Technology Media!
Register | Log in
   
 
.NET  ·  AJAX  ·  CLOUD  ·  ECLIPSE  ·  FLEX  ·  OPEN WEB  ·  iPHONE  ·  JAVA  ·  LINUX  ·  OPEN SOURCE  ·  ORACLE  ·  PBDJ  ·  SEARCH  ·  SILVERLIGHT  ·  SOA  ·  VIRTUALIZATION  ·  WEB 2.0  ·  WIRELESS  ·  XML
Comments
Plone and Drupal: Different Approaches, Different Results
paul.nowak wrote: Matt, thanks for the comments. I made an error on the version of Plone. It's 2.5 Plone running on Zope 2.9x. In regards to the additional products, we have a skin installed and we have a product that we had custom developed for us that connects to a PostgreSQL database. We've looked at slow PostgreSQL queries causing problems and have not been able to find an issue. We've also tested for the case where the PostgreSQL server is down and have not been able to create an issue. We therefor...
Nov. 4, 2009 04:19 PM EST
Cloud Expo on Google News
Did you read today's front page stories & breaking news?


2009 East
PLATINUM SPONSORS:
IBM
Smarter Business Solutions Through Dynamic Infrastructure
IBM
Smarter Insights: How the CIO Becomes a Hero Again
Microsoft
Windows Azure
GOLD SPONSORS:
Appsense
Why VDI?
CA
Maximizing the Business Value of Virtualization in Enterprise and Cloud Computing Environments
ExactTarget
Messaging in the Cloud - Email, SMS and Voice
Freedom OSS
Stairway to the Cloud
Sun
Sun's Incubation Platform: Helping Startups Serve the Enterprise
POWER PANELS:
Cloud Computing & Enterprise IT: Cost & Operational Benefits
How and Why is a Flexible IT Infrastructure the Key To the Future?
Click For 2008 West
Event Webcasts

2009 East
GOLD SPONSORS:
CA
Get Your Transactions Under Control: SOA Performance Management
Software AG
Performance Driven Adoption: The Secret to Advancing SOA
Intel
The Evolving SOA Appliance: 3 Game-Changing Innovations
SILVER SPONSOR:
Denodo
Data Mashups: Deliver Your Project Faster with Virtualized Data Services Across Internal & External Sources
POWER PANELS:
The Business Value of Service Orientation
Driving Profitability Through User Experience
Click For 2008 West
Event Webcasts
Live Google News by SYS-CON!
Top Three Links You Must Click On


Security Management
Enabling Desktop Virtualization in High-Risk Environments
Increased risk and an opportunity for better security

By: Karl MacMillan
Nov. 25, 2008 10:00 AM
  • 1
  • 2
  • next ›
  • last »

Server virtualization has moved well beyond the arena of early adopters and is an accepted solution to many of the challenges faced by IT organizations. However, desktop virtualization has not made the same inroads. Certainly, there have been some key uses for desktop virtualization, such as development and test, but there has not been broad penetration into the non-technical desktop market. There are signs that this trend is about to change.

The major virtualization vendors, including Citrix, VMware, and Microsoft, have recently released new or updated desktop virtualization products that aim to make virtualization as common on the desktop as in the data center. The value proposition is largely the same as on the server: rapid deployment, better hardware utilization, easier management, and increased separation of workloads.

At the same time, security and compliance concerns are pushing IT organizations to bring the same level of application and data separation common in the data center to the desktop. Just as it's now unimaginable to host Internet-facing applications on the same server as key internal applications, security and privacy concerns may make using a single desktop operating system for each user similarly unthinkable.

Given these trends, it would seem natural for organizations with high-risk environments, which have long recognized the need for strong separation on the desktop, to flock to desktop virtualization. These environments, traditionally found in government, utility, health care, and financial organizations, are driven by security concerns to utilize two or more physically separate desktop systems per user to protect internal systems and prevent confidential data from leaking. Consolidating these desktop systems using virtualization can dramatically reduce space, power, hardware, and management costs. However, despite these apparent advantages, security often remains a barrier to entry to adopting desktop virtualization solutions in these environments. These security concerns go beyond the separation and security features provided by typical desktop virtualization products.

To illustrate the security concerns of these high-risk environments, consider the recent high-profile emergency shutdown of the Hatch nuclear power plant near Baxley, Georgia, that was caused when a single computer system was updated. The computer system, which was connected to both the corporate network and the network dedicated to controlling the nuclear power plant, was updated by an administrator unaware of the two network connections. When the administrator rebooted the system, it caused the plant's safety systems to erroneously conclude that there was a drop in the water reservoirs used to cool the reactor, causing an emergency shutdown of the reactor. Thankfully, the shutdown proceeded smoothly and no one was in danger; however, it probably cost millions of dollars and required a full investigation by the Nuclear Regulatory Commission.

It was not simply a procedural problem that led an administrator to make updates to a system without fully understanding its function. The system was incorrectly connected to both networks, a mistake the plants technicians were aware of but hadn't corrected. While it's not clear from public information why this inappropriate connection was made, it underscores the importance of strict separation and isolation in these environments. Even a single lapse in network separation caused significant safety concerns in this environment. It also demonstrates why these organizations can't lightly adopt desktop virtualization in high-risk environments. As desktop virtualization solutions would be relied on to maintain this crucial network separation, it's critical that the solutions be carefully architected and engineered to provide the required level of security.

  • 1
  • 2
  • next ›
  • last »
Published Nov. 25, 2008— Reads 2,491
Copyright © 2008 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
About Karl MacMillan
Karl MacMillan is Tresys Technology's Director of the Linux Security Practice, author of "SELinux by Example: Using Security Enhanced Linux," and frequent speaker at virtualization, security and open source events nationwide. With experience spanning dozens of successful strong security implementations, delivering security products and services for some of the most sensitive security missions around the world, including those at defense and intelligence agencies globally, and through partnerships with IBM, General Dynamics, Red Hat and Cisco, Karl is an established security thought leader.

Add Your Feedback

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

SYS-CON Featured Whitepapers

ADS BY GOOGLE

Breaking Java News
GOL Announces Net Income of R$77.9mm in 3Q09
ITC^DeltaCom Announces Third Quarter 2009 Results
Mueller Water Products to Present at Oppenheimer's 4th Annual Industrials Conference
Western Sizzlin Corporation Completes Distribution of Special Dividend of Steak n Shake Shares
Opta Minerals Inc. Reports Third Quarter Results for Fiscal 2009
Farmer Mac Reports Third Quarter GAAP Earnings of $18 Million
Hydrogenics Files Universal Shelf Prospectus
CALL OF DUTY(R): MODERN WARFARE(R) 2, MICROSOFT AND GAMESTOP TAKE OVER UNION SQUARE
Gold Hawk Announces Board Change
Media Advisory: Governor General to Participate in Remembrance Day Events in Ottawa

ADVERTISE   |   MAGAZINE SUBSCRIPTIONS   |   FREE BREAKING-NEWSLETTERS!   |   SYS-CON.TV   |   BLOG-N-PLAY!   |   WEBCAST   |   EDUCATION   |   RESEARCH

.NET Developer's Journal - .NETDJ   |   ColdFusion Developer's Journal - CFDJ   |   Eclipse Developer's Journal - EDJ   |   Enterprise Open Source Magazine - EOS
Open Web Developer's Journal - OPENWEB   |   iPhone Developer's Journal - iPHONE   |   Virtualization - Virtualization   |   Java Developer's Journal - JDJ   |   Linux.SYS-CON.com
PowerBuilder Developer's Journal - PBDJ   |   SEO / SEM Journal - SJ   |   SOAWorld Magazine - SOAWM   |   IT Solutions Guide - ITSG   |   Symbian Developer's Journal - SDJ
WebLogic Developer's Journal - WLDJ   |   WebSphere Journal - WJ   |   Wireless Business & Technology - WBT   |   XML-Journal - XMLJ   |   Internet Video - iTV
Flex Developer's Journal - Flex   |   AJAXWorld Magazine - AWM   |   Silverlight Developer's Journal - SLDJ   |   PHP.SYS-CON.com   |   Web 2.0 Journal - WEB2
Apache   |   CMS   |   CRM   |   HP   |   Oracle Journal   |   Perl   |   Python   |   Red Hat   |   Ruby on Rails   |   SAP   |   SaaS

SYS-CON MEDIA:   ABOUT US   |   CONTACT US   |   COMPANY NEWS   |   CAREERS   |   SITE MAP
SYS-CON EVENTS:   |  AJAXWorld Conference & Expo  |  iPhone Developer Summit  |  Cloud Computing Conference & Expo  |  SOA World Conference & Expo  |  Virtualization Conference & Expo
INTERNATIONAL SITES:   India  |  U.K.  |  Canada  |  Germany  |  France  |  Australia  |  Italy  |  Spain  |  Netherlands  |  Brazil  |  Belgium
 Terms of Use & Our Privacy Statement     About Newsfeeds / Video Feeds
Copyright ©1994-2008 SYS-CON Publications, Inc. All Rights Reserved. All marks are trademarks of SYS-CON Media.
Reproduction in whole or in part in any form or medium without express written permission of SYS-CON Publications, Inc. is prohibited.
 
close this window