Chris Hoff posts about VMware's recently released DMZ whitepaper. It shows three different approaches to DMZ architectures and discusses their strengths and weaknesses: Partially collapsed with physical zone separation. In this architecture, you put VMs of the same trust level on the same physical boxes and separate them using traditional firewalls. Partially collapsed with virtual zone separation ...
Last week at the Burton Group conference I presented on the Top Ten Strategic Security Metrics. It is really interesting to see the reactions I get from people about these. Some security professionals get really excited about them while others think they are pie-in-the-sky. Rest assured, that even though these are strategic metrics, they have detailed grounding in operational metrics. That is the ...
Here it is: "This procedure can be likened to a hike with no navigational aids along a narrow, tortuous trail through a forest obscured by fog so impenetrable that one can see only one step ahead. As long as one remains on and follows the trail exactly, there is no ambiguity concerning the proper direction to walk in. As soon as one leaves the main trail, however, then returning to the original tr ...
I feel much better about virtualization security now that I've read this story. It turns out that virtualized environments are exactly the same as all other things IT from a security perspective. Says Nand Mulchanandi, security marketer for VMware: "Data centers are very tightly locked down, and virtual environments are no less tightly locked down than physical ones," he said. "It's really about p ...
Ryan Barnett of ModSecurity has an excellent post on web security metrics. He really nails the fact that it is the outcome that matters: "While some customers may be distracted by eye-catching graphical displays of this information, the savvy ones will ask this key question - Were there any successful attacks? The answer to this question will tell you the score of the game - did the opponent score ...