<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Security Blog</title>
    <link>http://viops.vmware.com/home/blogs/itsecurity</link>
    <description>Security and virtualization experts</description>
    <pubDate>Thu, 18 Jun 2009 18:41:24 GMT</pubDate>
    <generator>Clearspace 2.0.8 (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2009-06-18T18:41:24Z</dc:date>
    <item>
      <title>VMware vShield Zones 1.0 is generally available</title>
      <link>http://viops.vmware.com/home/blogs/itsecurity/2009/06/18/vmware-vshield-zones-10-is-generally-available</link>
      <description>&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Warren Wu writes over on the &lt;a class="jive-link-external-small" dynsrc="#" href="http://blogs.vmware.com/security/2009/06/vmware-vshield-zones-is-ga.html" lowsrc="#" src="#"&gt;VMware Security Blog&lt;/a&gt;:&lt;/p&gt;&lt;div class="jive-quote"&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;With the general availability of VMware vSphere 4 a few weeks ago, I just wanted to highlight for the security community that VMware vShield Zones is also part of that release and now generally available!&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;vShield Zones is a new product for VMware and one of the newest members of the vSphere 4 product family, based on technology from our acquisition of Blue Lane Technologies.  We had a lot of interest from customers around vShield Zones and had over 200 customers around the world registered for our recent private beta.  It is part of the vSphere package starting with the Advanced Edition and above.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;VMware vShield Zones 1.0 offers the following key features and benefits for vSphere 4 environments:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Central Management of Logical Zone Boundaries and Segmentation&lt;/strong&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Leverage existing virtual infrastructure containers –  hosts, virtual switches, VLANs – as logical trust or organizational  zones&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Define policies to bridge, firewall, or isolate network  traffic between zone boundaries&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Manage and deploy policies across entire VMware vCenter  Server deployment&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Integrate with VMware vCenter Server and automatically  deploy on existing virtual networks&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Scan and discover existing applications running on  virtual machines to identify application protocol&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Network Enforcement and Flow Monitoring&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Classify traffic by network or application protocol (e.g.  HTTP, RDP, SNMP)&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Performantly filter traffic with stateful packet  inspection (SPI)&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Track dynamic port connections for protocols such as  FTP&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Track network connections across VMware VMotion migration  events.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Easily convert observed network flows into precise  network enforcement rules.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Monitor both allowed and disallowed activity&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Management and Reporting&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Access the Web-based vShield Manager interface remotely  from any Web browser&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Configure administrators to be common with VMware vCenter  Server or distinct for separation of duties and roles&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;View activity hierarchically at individual virtual  machine or aggregate levels and generate graphical or tabular  reports&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Retain log data for archival and compliance  purposes&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Export events and data using syslog format&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span&gt;More information about vShield Zones can be found at the product page here: &lt;/span&gt;&lt;a class="jive-link-external-small" dynsrc="#" href="http://www.vmware.com/products/vshield-zones/" lowsrc="#" src="#"&gt;http://www.vmware.com/products/vshield-zones/&lt;/a&gt;&lt;span&gt; &amp;lt;&lt;/span&gt;&lt;a class="jive-link-external-small" dynsrc="#" href="http://www.vmware.com/products/vshield-zones/&amp;gt;" lowsrc="#" src="#"&gt;http://www.vmware.com/products/vshield-zones/&amp;gt;&lt;/a&gt;&lt;span&gt; &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span&gt;vShield Zones 1.0 is downloadable as part of the VMware vSphere evaluation at: &lt;/span&gt;&lt;a class="jive-link-external-small" dynsrc="#" href="https://www.vmware.com/tryvmware/index.php?p=vsphere&amp;amp;lp=1" lowsrc="#" src="#"&gt;https://www.vmware.com/tryvmware/index.php?p=vsphere&amp;amp;lp=1&lt;/a&gt;&lt;span&gt; &amp;lt;&lt;/span&gt;&lt;a class="jive-link-external-small" dynsrc="#" href="https://www.vmware.com/tryvmware/index.php?p=vsphere&amp;amp;lp=1&amp;gt;" lowsrc="#" src="#"&gt;https://www.vmware.com/tryvmware/index.php?p=vsphere&amp;amp;lp=1&amp;gt;&lt;/a&gt;&lt;span&gt; &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span&gt;Documentation and release notes about vShield Zones 1.0 can be found at: &lt;/span&gt;&lt;a class="jive-link-external-small" dynsrc="#" href="http://www.vmware.com/support/pubs/vsz_pubs.html" lowsrc="#" src="#"&gt;http://www.vmware.com/support/pubs/vsz_pubs.html&lt;/a&gt;&lt;span&gt; &amp;lt;&lt;/span&gt;&lt;a class="jive-link-external-small" dynsrc="#" href="http://www.vmware.com/support/pubs/vsz_pubs.html&amp;gt;" lowsrc="#" src="#"&gt;http://www.vmware.com/support/pubs/vsz_pubs.html&amp;gt;&lt;/a&gt;&lt;span&gt; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;/div&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;/div&gt;</description>
      <pubDate>Thu, 18 Jun 2009 18:47:15 GMT</pubDate>
      <author>charu@vmware.com</author>
      <guid>http://viops.vmware.com/home/blogs/itsecurity/2009/06/18/vmware-vshield-zones-10-is-generally-available</guid>
      <dc:date>2009-06-18T18:47:15Z</dc:date>
      <clearspace:dateToText>5 months, 1 week ago</clearspace:dateToText>
      <wfw:comment>http://viops.vmware.com/home/blogs/itsecurity/comment/vmware-vshield-zones-10-is-generally-available</wfw:comment>
      <wfw:commentRss>http://viops.vmware.com/home/blogs/itsecurity/feeds/comments?blogPost=1106</wfw:commentRss>
    </item>
    <item>
      <title>Beta of VMware vShield Zones</title>
      <link>http://viops.vmware.com/home/blogs/itsecurity/2009/03/26/beta-of-vmware-vshield-zones</link>
      <description>&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Recently at VMworld Europe 2009 in February, VMware announced a new vSphere offering called VMware vShield Zones that provides network monitoring and firewalling for security and compliance of VM's.   vShield Zones is based on our acquistion of Blue Lane Technologies last October.  It is uses Blue Lane's mature application-aware network stack, but instead of offering virtual patching, it has all-new modules providing network flowing monitoring/auditing as well as network firewalling. These are packaged as a virtual appliance and provides visibility and enforcement specifically for logically partitioning the interior of the virtual datacenter.  &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span&gt;We recent started a private beta open to vSphere beta customers that will be running for the next few weeks.  If you are interested, please send me a private message.  You can learn more about VMware vShield Zones at the product page here: &lt;/span&gt;&lt;a class="jive-link-external-small" dynsrc="#" href="http://www.vmware.com/products/vshield-zones/" lowsrc="#" src="#"&gt;http://www.vmware.com/products/vshield-zones/&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;/div&gt;</description>
      <pubDate>Thu, 26 Mar 2009 20:15:39 GMT</pubDate>
      <author>charu@vmware.com</author>
      <guid>http://viops.vmware.com/home/blogs/itsecurity/2009/03/26/beta-of-vmware-vshield-zones</guid>
      <dc:date>2009-03-26T20:15:39Z</dc:date>
      <clearspace:dateToText>8 months, 1 day ago</clearspace:dateToText>
      <wfw:comment>http://viops.vmware.com/home/blogs/itsecurity/comment/beta-of-vmware-vshield-zones</wfw:comment>
      <wfw:commentRss>http://viops.vmware.com/home/blogs/itsecurity/feeds/comments?blogPost=1099</wfw:commentRss>
    </item>
    <item>
      <title>Virtualization and Compliance</title>
      <link>http://viops.vmware.com/home/blogs/itsecurity/2008/10/17/virtualization-and-compliance</link>
      <description>&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Virtualization Compliance has become a hot topic lately, particularly in the retail environment.  For that industry, there are a confluence of factors that have come together:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;The imposition of the PCI standards on the majority of merchants who process credit cards&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;The fact that PCI is one of the more prescriptive security standards out there, but yet does not acknowledge virtualization as a technology &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;The growing desire for retailers to virtualize their store environments, due to the tremendous savings that can be achieved when server consolidation is leveraged across hundreds or even thousands of locations&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Other standards such as HIPAA and SOX are of course top of mind for IT administrators in those respective industries, and I expect to see more direct questions from virtualization admins in those areas as time goes on.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;To help answer the question, "how can I achieve compliance in my virtualized environment", we recently launched the &lt;a class="jive-link-external-small" dynsrc="#" href="http://vmware.com/go/compliance" lowsrc="#" src="#"&gt;VMware Compliance Center&lt;/a&gt;.   We have provided some overview information, a list of partner solutions that can help with achieving, maintaining, and demonstrating compliance, and a list of resources, including whitepapers, webcasts, and podcasts from leading vendors in this area.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I would love to here comments from people both on what more you'd like to see in the Compliance Center, as well as on what are the burning issues that you face with compliance, and maybe some tips or lessons learned that you can share with others.&lt;/p&gt;&lt;/div&gt;</description>
      <pubDate>Fri, 17 Oct 2008 18:35:14 GMT</pubDate>
      <author>charu@vmware.com</author>
      <guid>http://viops.vmware.com/home/blogs/itsecurity/2008/10/17/virtualization-and-compliance</guid>
      <dc:date>2008-10-17T18:35:14Z</dc:date>
      <clearspace:dateToText>1 year, 1 month ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
      <wfw:comment>http://viops.vmware.com/home/blogs/itsecurity/comment/virtualization-and-compliance</wfw:comment>
      <wfw:commentRss>http://viops.vmware.com/home/blogs/itsecurity/feeds/comments?blogPost=1064</wfw:commentRss>
    </item>
    <item>
      <title>Xtravirt's Security Risk Assessment</title>
      <link>http://viops.vmware.com/home/blogs/itsecurity/2008/09/03/xtravirts-security-risk-assessment</link>
      <description>&lt;div class='jive-rendered-content'&gt;&lt;p&gt;&lt;a class="jive-link-email-small" dynsrc="#" href="mailto:people/gavin.joliffe@xtravirt.com" lowsrc="#" src="#"&gt;Gavin Joliffe&lt;/a&gt; of &lt;a class="jive-link-external-small" dynsrc="#" href="http://www.xtravirt.com" lowsrc="#" src="#"&gt;Xtravirt&lt;/a&gt; was one of the very first contributors to VIOPS with a &lt;a class="jive-link-wiki-small" dynsrc="#" href="http://viops.vmware.com/home/docs/DOC-1032" lowsrc="#" src="#"&gt;Proven Practice: VI3 Security Risk Assessment.&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;You're reading this because you already know that security is a key part of virtualization, probably because it changes the game somewhat.  Being ever the optimist, I'm a fan of saying "enhanced" instead of "changed" or "broken", but that's just my sunny Yorkshire disposition.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;What Xtravirt have done in their document is to encapsulate their experience of running their own security process for virtualization for themselves (prior to starting Xtravirt) and now on behalf of clients - that's a lot of experience!&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;That is the kind of document and experience we need for VIOPS proven practices.  Instead of trying to create something that tries to be all things to all people, Xtravirt have focussed in on what has been successful for them and written it up.  &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Steve &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;/div&gt;</description>
      <category domain="http://viops.vmware.com/home/blogs/itsecurity/tags">xtravirt</category>
      <category domain="http://viops.vmware.com/home/blogs/itsecurity/tags">risk_assessment</category>
      <pubDate>Wed, 03 Sep 2008 17:43:02 GMT</pubDate>
      <author>schambers</author>
      <guid>http://viops.vmware.com/home/blogs/itsecurity/2008/09/03/xtravirts-security-risk-assessment</guid>
      <dc:date>2008-09-03T17:43:02Z</dc:date>
      <clearspace:dateToText>1 year, 2 months ago</clearspace:dateToText>
      <wfw:comment>http://viops.vmware.com/home/blogs/itsecurity/comment/xtravirts-security-risk-assessment</wfw:comment>
      <wfw:commentRss>http://viops.vmware.com/home/blogs/itsecurity/feeds/comments?blogPost=1058</wfw:commentRss>
    </item>
  </channel>
</rss>

