0

Cloud computing is one of the IT-game changers of our time but security and compliance concerns are holding cloud computing (Infrastructure as a Service) adoption to less than 1% of participants in Nemertes’ benchmark research.

At the heart of cloud computing is virtualization, which abstracts data, applications and operating systems from underlying hardware and in the process marginalizes security practices dependent on physical devices, a hard perimeter, and static boundaries and locations. Virtualization injects movement and dynamism into the IT Infrastructure and introduces a new layer of software and an ecosystem of related management applications that needs its own protection. These are all things that don’t exist in the non-virtualized infrastructure. Since over 90% of organizations are already deploying virtualization, much of our discussion will focus on virtualization security (VirtSec).

Beyond virtualization, cloud computing adds an additional layer of abstraction, raising additional security-related issues, including: Compliance, defense in depth, data location, privacy, shared tenancy, data leakage, data retention, e-Discovery, standards and performance. Addressing these issues requires more than simply slapping on some VirtSec. We must fundamentally rethink data security, depending on whether we’re protecting internal, external or hybrid cloud environments. Many of the underlying security controls are the same: Encryption, strong (multi-factor) authentication, access controls, audit logs, intrusion detection, anti-malware, anti-virus, etc. What’s different is the context, the way we apply these controls and new controls that are only possible in a virtualized infrastructure with virtualized security. The bottom line is we’ve got a lot to talk about.

Continue Reading

0

Apple has released a massive security update containing 47 fixes for a host of platforms.

The patch covers flaws in the Mac OSX, the iPhone and the QuickTime media player. The OSX patches cover both Leopard and Snow Leopard operating systems as well as interoperability with third party software from Adobe Flash, Samba, MySQL and PHP.

The patch fixes 33 vulnerabilities in the Leopard operating system, while Snow Leopard received just a single fix.

Apple’s iPhone got patches for a variety of problems, including CoreAudio, WebKit and MobileMail, which the QuickTime update included four patches, some of which were critical in that they allowed remote takeover of a user’s computer using properly crafted malware.

One of the more worrying series of patches covered the ClamAV antivirus product Apple is using. They covered serious flaws that would allow remote code execution of systems being attacked.

The company has also issued another Flash update, in addition to last week’s update on the flawed software.

Continue Reading

PHVsPjxsaT48c3Ryb25nPndvb19hZHNfcm90YXRlPC9zdHJvbmc+IC0gdHJ1ZTwvbGk+PGxpPjxzdHJvbmc+d29vX2FkX2NvbnRlbnRfYWRzZW5zZTwvc3Ryb25nPiAtIDwvbGk+PGxpPjxzdHJvbmc+d29vX2FkX2NvbnRlbnRfZGlzYWJsZTwvc3Ryb25nPiAtIGZhbHNlPC9saT48bGk+PHN0cm9uZz53b29fYWRfY29udGVudF9pbWFnZTwvc3Ryb25nPiAtIGh0dHA6Ly93d3cud29vdGhlbWVzLmNvbS9hZHMvd29vdGhlbWVzLTQ2OHg2MC0yLmdpZjwvbGk+PGxpPjxzdHJvbmc+d29vX2FkX2NvbnRlbnRfdXJsPC9zdHJvbmc+IC0gaHR0cDovL3d3dy53b290aGVtZXMuY29tPC9saT48bGk+PHN0cm9uZz53b29fYWRfaW1hZ2VfMTwvc3Ryb25nPiAtIGh0dHA6Ly93d3cud29vdGhlbWVzLmNvbS9hZHMvd29vdGhlbWVzLTEyNXgxMjUtMS5naWY8L2xpPjxsaT48c3Ryb25nPndvb19hZF9pbWFnZV8yPC9zdHJvbmc+IC0gaHR0cDovL3d3dy53b290aGVtZXMuY29tL2Fkcy93b290aGVtZXMtMTI1eDEyNS0yLmdpZjwvbGk+PGxpPjxzdHJvbmc+d29vX2FkX2ltYWdlXzM8L3N0cm9uZz4gLSBodHRwOi8vd3d3Lndvb3RoZW1lcy5jb20vYWRzL3dvb3RoZW1lcy0xMjV4MTI1LTMuZ2lmPC9saT48bGk+PHN0cm9uZz53b29fYWRfaW1hZ2VfNDwvc3Ryb25nPiAtIGh0dHA6Ly93d3cud29vdGhlbWVzLmNvbS9hZHMvd29vdGhlbWVzLTEyNXgxMjUtNC5naWY8L2xpPjxsaT48c3Ryb25nPndvb19hZF91cmxfMTwvc3Ryb25nPiAtIGh0dHA6Ly93d3cud29vdGhlbWVzLmNvbTwvbGk+PGxpPjxzdHJvbmc+d29vX2FkX3VybF8yPC9zdHJvbmc+IC0gaHR0cDovL3d3dy53b290aGVtZXMuY29tPC9saT48bGk+PHN0cm9uZz53b29fYWRfdXJsXzM8L3N0cm9uZz4gLSBodHRwOi8vd3d3Lndvb3RoZW1lcy5jb208L2xpPjxsaT48c3Ryb25nPndvb19hZF91cmxfNDwvc3Ryb25nPiAtIGh0dHA6Ly93d3cud29vdGhlbWVzLmNvbTwvbGk+PGxpPjxzdHJvbmc+d29vX2FsdF9zdHlsZXNoZWV0PC9zdHJvbmc+IC0gYmx1ZW9yYW5nZS5jc3M8L2xpPjxsaT48c3Ryb25nPndvb19hdXRvX2ltZzwvc3Ryb25nPiAtIGZhbHNlPC9saT48bGk+PHN0cm9uZz53b29fYmxvZ19jYXRfaWQ8L3N0cm9uZz4gLSAxPC9saT48bGk+PHN0cm9uZz53b29fYmxvZ19uYXZpZ2F0aW9uPC9zdHJvbmc+IC0gdHJ1ZTwvbGk+PGxpPjxzdHJvbmc+d29vX2Jsb2dfbmF2aWdhdGlvbl9mb290ZXI8L3N0cm9uZz4gLSB0cnVlPC9saT48bGk+PHN0cm9uZz53b29fYmxvZ19wZXJtYWxpbms8L3N0cm9uZz4gLSAvP2NhdD0xPC9saT48bGk+PHN0cm9uZz53b29fYmxvZ19zaWRlYmFyPC9zdHJvbmc+IC0gQmxvZyBQYWdlczwvbGk+PGxpPjxzdHJvbmc+d29vX2Jsb2dfc3VibmF2aWdhdGlvbjwvc3Ryb25nPiAtIGZhbHNlPC9saT48bGk+PHN0cm9uZz53b29fYnJlYWRjcnVtYnM8L3N0cm9uZz4gLSB0cnVlPC9saT48bGk+PHN0cm9uZz53b29fY3VzdG9tX2Nzczwvc3Ryb25nPiAtIDwvbGk+PGxpPjxzdHJvbmc+d29vX2N1c3RvbV9mYXZpY29uPC9zdHJvbmc+IC0gPC9saT48bGk+PHN0cm9uZz53b29fZGlzY2xhaW1lcjwvc3Ryb25nPiAtIFBvc3Q6IEJhbGx5bWFjb3dlbiwgQ2xvbmFraWx0eSwgQ28uIENvcmsNCjxici8+DQpDb3B5cmlnaHQ6IDIwMDkgTmV4dXMgVGVjaG5vbG9naWVzIDxicj4NCldlYnNpdGUgYnk6IDxhIGhyZWY9XCJodHRwOi8vd3d3LmJhc2VjcmVhdGl2ZS5pZVwiIHRpdGxlPVwiIFdlYnNpdGUgRGVzaWduIFNFTyBDb21wYW55IGluIER1YmxpbiBCYXNlIENyZWF0aXZlXCI+QmFzZSBDcmVhdGl2ZTwvYT48L2xpPjxsaT48c3Ryb25nPndvb19leGNsdWRlX3BhZ2VzX2Zvb3Rlcjwvc3Ryb25nPiAtIDE4LDIxLDI0LDI2LDI4LDMwLDQ0LDQ2LDQ5LDY1LDc0LDgyLDg5LDgwODwvbGk+PGxpPjxzdHJvbmc+d29vX2V4Y2x1ZGVfcGFnZXNfbWFpbjwvc3Ryb25nPiAtIDE4LDg5PC9saT48bGk+PHN0cm9uZz53b29fZXhjbHVkZV9wYWdlc19zdWJuYXY8L3N0cm9uZz4gLSA8L2xpPjxsaT48c3Ryb25nPndvb19mZWF0X2hlaWdodDwvc3Ryb25nPiAtIDIwMDwvbGk+PGxpPjxzdHJvbmc+d29vX2ZlYXRfd2lkdGg8L3N0cm9uZz4gLSA2NDE8L2xpPjxsaT48c3Ryb25nPndvb19mZWVkYnVybmVyX3VybDwvc3Ryb25nPiAtIDwvbGk+PGxpPjxzdHJvbmc+d29vX2dvb2dsZV9hbmFseXRpY3M8L3N0cm9uZz4gLSA8c2NyaXB0IHR5cGU9XCJ0ZXh0L2phdmFzY3JpcHRcIj4NCnZhciBnYUpzSG9zdCA9ICgoXCJodHRwczpcIiA9PSBkb2N1bWVudC5sb2NhdGlvbi5wcm90b2NvbCkgPyBcImh0dHBzOi8vc3NsLlwiIDogXCJodHRwOi8vd3d3LlwiKTsNCmRvY3VtZW50LndyaXRlKHVuZXNjYXBlKFwiJTNDc2NyaXB0IHNyYz1cJ1wiICsgZ2FKc0hvc3QgKyBcImdvb2dsZS1hbmFseXRpY3MuY29tL2dhLmpzXCcgdHlwZT1cJ3RleHQvamF2YXNjcmlwdFwnJTNFJTNDL3NjcmlwdCUzRVwiKSk7DQo8L3NjcmlwdD4NCjxzY3JpcHQgdHlwZT1cInRleHQvamF2YXNjcmlwdFwiPg0KdHJ5IHsNCnZhciBwYWdlVHJhY2tlciA9IF9nYXQuX2dldFRyYWNrZXIoXCJVQS0xMDExMDE4Ni0xXCIpOw0KcGFnZVRyYWNrZXIuX3RyYWNrUGFnZXZpZXcoKTsNCn0gY2F0Y2goZXJyKSB7fTwvc2NyaXB0Pg0KPC9saT48bGk+PHN0cm9uZz53b29faG9tZXBhZ2U8L3N0cm9uZz4gLSBsYXlvdXQtZGVmYXVsdC5waHA8L2xpPjxsaT48c3Ryb25nPndvb19ob21lX3NpZGViYXI8L3N0cm9uZz4gLSBIb21lcGFnZTwvbGk+PGxpPjxzdHJvbmc+d29vX2luY19pbnRyb19wYWdlPC9zdHJvbmc+IC0gZmFsc2U8L2xpPjxsaT48c3Ryb25nPndvb19pbmNfaW50cm9fcGFnZV9sZWZ0PC9zdHJvbmc+IC0gZmFsc2U8L2xpPjxsaT48c3Ryb25nPndvb19pbmNfaW50cm9fcGFnZV9yaWdodDwvc3Ryb25nPiAtIGZhbHNlPC9saT48bGk+PHN0cm9uZz53b29faW5jX3RhYmJlcl9wYWdlczwvc3Ryb25nPiAtIGZhbHNlPC9saT48bGk+PHN0cm9uZz53b29faW50cm9fcGFnZTwvc3Ryb25nPiAtIDE4PC9saT48bGk+PHN0cm9uZz53b29faW50cm9fcGFnZV9sZWZ0PC9zdHJvbmc+IC0gODk8L2xpPjxsaT48c3Ryb25nPndvb19pbnRyb19wYWdlX3JpZ2h0PC9zdHJvbmc+IC0gMzI8L2xpPjxsaT48c3Ryb25nPndvb19sb2dvPC9zdHJvbmc+IC0gaHR0cDovL3d3dy5uZXh1c3RlY2hub2xvZ2llcy50di9pbWFnZXMvbG9nby5wbmcgPC9saT48bGk+PHN0cm9uZz53b29fbWFnX2ZlYXR1cmVkPC9zdHJvbmc+IC0gMzwvbGk+PGxpPjxzdHJvbmc+d29vX21hZ19zZWNvbmRhcnk8L3N0cm9uZz4gLSBTZWxlY3QgYSBudW1iZXI6PC9saT48bGk+PHN0cm9uZz53b29fbWFudWFsPC9zdHJvbmc+IC0gaHR0cDovL3d3dy53b290aGVtZXMuY29tL3N1cHBvcnQvdGhlbWUtZG9jdW1lbnRhdGlvbi90aGUtc3RhdGlvbi88L2xpPjxsaT48c3Ryb25nPndvb19wYWdlX3NpZGViYXI8L3N0cm9uZz4gLSBJbm5lciBQYWdlczwvbGk+PGxpPjxzdHJvbmc+d29vX3Jlc2l6ZTwvc3Ryb25nPiAtIHRydWU8L2xpPjxsaT48c3Ryb25nPndvb19zaG9ydG5hbWU8L3N0cm9uZz4gLSB3b288L2xpPjxsaT48c3Ryb25nPndvb19zbGlkZXI8L3N0cm9uZz4gLSBmYWxzZTwvbGk+PGxpPjxzdHJvbmc+d29vX3NtYWxsdGh1bWJfaGVpZ2h0PC9zdHJvbmc+IC0gNDI8L2xpPjxsaT48c3Ryb25nPndvb19zbWFsbHRodW1iX3dpZHRoPC9zdHJvbmc+IC0gNTY8L2xpPjxsaT48c3Ryb25nPndvb19zdWJuYXY8L3N0cm9uZz4gLSBmYWxzZTwvbGk+PGxpPjxzdHJvbmc+d29vX3RhYmJlcl9wYWdlczwvc3Ryb25nPiAtIDM0LDQyLDgyPC9saT48bGk+PHN0cm9uZz53b29fdGhlbWVuYW1lPC9zdHJvbmc+IC0gVGhlIFN0YXRpb248L2xpPjxsaT48c3Ryb25nPndvb190aGVfY29udGVudDwvc3Ryb25nPiAtIHRydWU8L2xpPjxsaT48c3Ryb25nPndvb190aHVtYl9oZWlnaHQ8L3N0cm9uZz4gLSA3NjwvbGk+PGxpPjxzdHJvbmc+d29vX3RodW1iX3dpZHRoPC9zdHJvbmc+IC0gMTAwPC9saT48bGk+PHN0cm9uZz53b29fdHdpdHRlcjwvc3Ryb25nPiAtIG5leHVzdGVjaDwvbGk+PC91bD4=