<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; Compliance</title>
	<atom:link href="http://www.vminformer.com/category/security/compliance/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.vminformer.com</link>
	<description></description>
	<lastBuildDate>Wed, 25 Jan 2012 11:58:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<item>
		<title>PCI-DSS Guidelines for Virtualization</title>
		<link>http://www.vminformer.com/pci-dss-guidelines-for-virtualization/</link>
		<comments>http://www.vminformer.com/pci-dss-guidelines-for-virtualization/#comments</comments>
		<pubDate>Fri, 24 Jun 2011 06:45:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[company news]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Virtualization Security]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[PCI-DSS Virtualization guidelines]]></category>
		<category><![CDATA[PCI-DSS Virtualization Security]]></category>

		<guid isPermaLink="false">http://www.vminformer.com/?p=2320</guid>
		<description><![CDATA[The latest guidelines from the PCI Security council recognize the need for carrying out thorough auditing and monitoring of virtual environments that fall under the remit of PCI requirements. Compared to traditional monitoring tools for a physical network, tools for virtual systems may not provide the same level of insight or monitoring within intra-host communications &#8230; <a href="http://www.vminformer.com/pci-dss-guidelines-for-virtualization/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The latest guidelines from the PCI Security council recognize the need for carrying out thorough auditing and monitoring of virtual environments that fall under the remit of PCI requirements.</p>
<blockquote><p>Compared to traditional monitoring tools for a physical network, tools for virtual systems may not provide the same level of insight or monitoring within intra-host communications or traffic flowing between VMs on a virtual network.</p></blockquote>
<p>They then  lead on to say:</p>
<blockquote><p>Similarly, specialized tools for monitoring and logging virtual environments may be needed to capture the level of detail required from the multiple components, including hypervisors, management interfaces, virtual machines, host systems, and virtual appliances.</p></blockquote>
<p>VMinformer can help organizations rapidly audit and monitor virtual environments that need to meet PCI-DSS compliance regulations. We ship with out of the box policy templates based on a number of industry standards including PCI-DSS.  To find out how sign up for a no obligation <a href="http://www.vminformer.com/trial-edition">14-day trial here.</a></p>
<p>PCI Security Standards Virtualization Guidelines Reference -<a href="https://www.pcisecuritystandards.org/documents/Virtualization_InfoSupp_v2.pdf">PCI-DSS Guidelines for virtualization</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/home/?status=PCI-DSS+Guidelines+for+Virtualization+http%3A%2F%2Ftinyurl.com%2F689kqfd" title="Post to Twitter"><img class="nothumb" src="http://www.vminformer.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-big3.png" alt="Post to Twitter" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.vminformer.com/pci-dss-guidelines-for-virtualization/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Get PCI DSS Compliant with VMinformer</title>
		<link>http://www.vminformer.com/pci-dss-compliant-vminformer/</link>
		<comments>http://www.vminformer.com/pci-dss-compliant-vminformer/#comments</comments>
		<pubDate>Wed, 02 Feb 2011 11:13:40 +0000</pubDate>
		<dc:creator>spiv</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[VMinformer]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[VMware compliance and auditing]]></category>

		<guid isPermaLink="false">http://www.vminformer.com/?p=1749</guid>
		<description><![CDATA[This week VMinformer has released a PCI DSS policy to assist your organization in passing the virtualization requirements as detailed in PCI DSS v2.0 . To find out how and why VMinformer can help your organization download a free trial today. VMinformer uncovers and finds issues that if left will impact the day to day &#8230; <a href="http://www.vminformer.com/pci-dss-compliant-vminformer/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>This week VMinformer has released a PCI DSS policy to assist your organization in passing the virtualization requirements as detailed in <a href="http://www.pcisecuritystandards.org">PCI DSS v2.0 </a>.  To find out how and why VMinformer can help your organization download a <a href="http://www.vminformer.com/support/resources/vmware-security/">free trial today.</a>  VMinformer uncovers and finds issues that if left will impact the day to day operations, security and performance of your organizations business!</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/home/?status=Get+PCI+DSS+Compliant+with+VMinformer+http%3A%2F%2Ftinyurl.com%2F4uf4gr8" title="Post to Twitter"><img class="nothumb" src="http://www.vminformer.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-big3.png" alt="Post to Twitter" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.vminformer.com/pci-dss-compliant-vminformer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Good Design, Good Security? Not Necessarily!</title>
		<link>http://www.vminformer.com/good-design-good-security-not-necessarily/</link>
		<comments>http://www.vminformer.com/good-design-good-security-not-necessarily/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 16:23:03 +0000</pubDate>
		<dc:creator>spiv</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[newsfeed]]></category>
		<category><![CDATA[Virtualization Security]]></category>
		<category><![CDATA[Good virtualization security design]]></category>
		<category><![CDATA[virtualizations security]]></category>

		<guid isPermaLink="false">http://www.vminformer.com/?p=1358</guid>
		<description><![CDATA[Everyone talks about good design principles when it comes to securing network infrastructures. It doesn&#8217;t matter if you are in a physical or virtual environment these basic design principles apply. But in reality especially in a virtual world are they enough combined with other techniques to raise the bar in terms of security? Design The &#8230; <a href="http://www.vminformer.com/good-design-good-security-not-necessarily/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Everyone talks about good design principles when it comes to securing network infrastructures.  It doesn&#8217;t matter if you are in a physical or virtual environment these basic design principles apply.  But in reality especially in a virtual world are they enough combined with other techniques to raise the bar in terms of security?</p>
<h2><span style="color: #1e8eba;">Design</span></h2>
<p><img src="http://www.vminformer.com/image/VMware-design-BP.png" alt="Good Design" /></p>
<p>The above design is taken from VMware&#8217;s own best practice guidelines for good network design topology.  I&#8217;m not going to discuss if it is right or wrong what I am going to be asking is it right for you and should you just copy it?</p>
<h2><span style="color: #1e8eba;">Should I Copy Design&#8217;s?</span></h2>
<p>Depends how good they are I guess? But bottom line NO NO NO, DON&#8217;T BE STUPID!<br />
Would you after all leave your keys in your front door or give a shotgun to your kids to play with?<br />
Plenty of people and organizations have been guilty of the above even to the level of copying IP address information and default usernames and passwords.</p>
<p>If I had a dollar every time I heard someone say isolate the management network or isolate this network I would be a rich man. Isolation alone does not guarantee security.  It can help for sure but unlike the physical world it only takes a few clicks to add a new virtual network interface to a server and hey presto you have just bypassed your firewall by linking your DMZ servers to your internal LAN.</p>
<h2><span style="color: #1e8eba;">Virtualization Security, VirtSec, Security Virtualization?</span></h2>
<p>Slightly different things depending on your perspective.  Virtualization isn&#8217;t necessarily any less secure or more secure than traditional physical infrastructure, some people might differ!  Virtualization because of its dynamic nature just lends itself to becoming less secure either because of lack of knowledge, the gun-ho approach taken to roll it out or just plain and simple mistakes combined with not enough awareness.</p>
<p>Surely if I have a firewall and install anti-virus and various other security measures I must be secure it&#8217;s better than nothing right?  Not necessarily so in my opinion you will be giving yourself a false sense of security.</p>
<h2><span style="color: #1e8eba;">Know your Enemy and Risks</span></h2>
<p>Ultimately know your enemy or at least have an idea and understand what your risks are.  What are you ultimately trying to protect?  If it is data which invariably it is where is it?, how is currently protected? and how valuable is it compared to the controls you need to put in place to protect it?  When doing a risk analysis work out the series of events that could occur and then evaluate them on how likely they are to occur and then weight them.  Going through this kind of exercise will prove invaluable later on and may turn up some interesting results that you may never have thought of.</p>
<h2><span style="color: #1e8eba;">Know what&#8217;s going on&#8230;</span></h2>
<p>AUDIT, AUDIT and AUDIT some more. If you don&#8217;t keep any eye on what is going on in your virtual environment you will never be able to provide adequate security measures to protect it.  Don&#8217;t just simply do this for a tick in the box for compliance.  Do this because you need to drive security measures within your virtual environment and be able to provide accountability not just lip service to the compliance auditors.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/home/?status=Good+Design%2C+Good+Security%3F+Not+Necessarily%21+http%3A%2F%2Ftinyurl.com%2F3yyzwq5" title="Post to Twitter"><img class="nothumb" src="http://www.vminformer.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-big3.png" alt="Post to Twitter" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.vminformer.com/good-design-good-security-not-necessarily/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virtual Compliance Auditing Tool</title>
		<link>http://www.vminformer.com/virtual-compliance-auditing-tool/</link>
		<comments>http://www.vminformer.com/virtual-compliance-auditing-tool/#comments</comments>
		<pubDate>Thu, 02 Apr 2009 13:08:59 +0000</pubDate>
		<dc:creator>spiv</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Virtualization Security]]></category>
		<category><![CDATA[VMinformer]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[compliance assessment]]></category>
		<category><![CDATA[security audit]]></category>

		<guid isPermaLink="false">http://www.vminformer.com/?p=349</guid>
		<description><![CDATA[Compliance Audit? If you are looking to assess the security of your virtual infrastructure as well as audit your VMware infrastructure for compliance reasons, what current options are available? Well you can start by looking at the VMware security hardening guidelines document available at this link which is a good document and can be complimented &#8230; <a href="http://www.vminformer.com/virtual-compliance-auditing-tool/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><span style="color: #0000ff;">Compliance Audit?</span></p>
<p><span style="color: #666699;">If you are looking to assess the security of your virtual infrastructure as well as audit your VMware infrastructure for compliance reasons, what current options are available?</span></p>
<p><span style="color: #666699;">Well you can start by looking at the VMware security hardening guidelines document available at <a title="security" href="http://www.vmware.com/security" target="_blank">this link</a> which is a good document and can be complimented by other documents such as those from CIS and DISA.  However the information contained in these documents has to be manually applied to your infrastructure which is all well and good if you only have a couple of Virtual machines and one ESX host but when you have 20 + machines to check then this process quickly becomes very time consuming and unrealistic.</span></p>
<p><span style="color: #0000ff;">So whats the answer?</span></p>
<p><span style="color: #666699;">Well there is a a comprehensive tool available called VMinformer that can do the job for you and will very rapidly check your entire Virtual Infrastructure in a matter of minutes against known industry best practices such as the ones mentioned above.</span></p>
<p><span style="color: #0000ff;">Reporting<br />
</span></p>
<p><span style="color: #666699;">The tool provides reports that can be handed over to your auditors or used in your own reports to meet PCI or similar industry compliance regulations.</span></p>
<p><span style="color: #666699;">To find out more go to <a title="vminformer compliance auditing tool" href="http://www.vminformer.com/" target="_self">vminformer.com</a><br />
</span></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/home/?status=Virtual+Compliance+Auditing+Tool+http%3A%2F%2Ftinyurl.com%2F3539b4j" title="Post to Twitter"><img class="nothumb" src="http://www.vminformer.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-big3.png" alt="Post to Twitter" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.vminformer.com/virtual-compliance-auditing-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

