Security and not-so-security within Virtualization

This article gives a brief overview of what virtualization is and lists some security interest to organizations that may utilize virtualized resources in their network. Following the benefits, the article highlights some security concerns when virtualization is used. Cloud providers are regularly referenced within the article as well, as the domains within the past CompTIA Security + 601 exam heavily include cloud computing.

SECURITY +

Olaf Madejski

2/4/20253 min read

This article gives a brief overview of what virtualization is and lists some security interest to organizations that may utilize virtualized resources in their network. Following the benefits, the article highlights some security concerns when virtualization is used. Cloud providers are regularly referenced within the article as well, as the domains within the past CompTIA Security + 601 exam heavily include cloud computing. The domains form the CompTIA Security+ 601 exam includes

2.1 – Explain the importance of security concepts in an enterprise environment.

2.2 – Summarize virtualization and cloud computing concepts.

3.6 – Given a scenario, apply cybersecurity solutions to the cloud.

5.2 – Explain the importance of applicable regulations, standards, or frameworks that impact organizational security posture.

The term Virtualization is defined in the CompTIA Network + Study Guide Exam N10-009 by Sybex glossary as; “Virtualization - The segmentation of processes on the shared resources of a server or cloud that allows processes to operate as if they had dedicated or physical resources.”[1] Simply put, virtualization is when an organization uses physical resources from a cloud provider carry out tasks for the overall benefit of the company whether it be for security, financial, or general efficiency.

Overview

What is virtualization?

What is Cloud Computing?

Cloud computing is a simple concept in which a cloud service provider delivers computing services to customers over the internet. The model enables customers to utilize computing resources such as networks, storage, server, or applications from a pool of shared resources managed by a cloud service provider and often requiring very little interaction to the cloud provider or management from the customer side.[2]

Conclusion

Security through cloud computing

Segmentation

What is virtualization?

Overall, virtualization and cloud computing can offer many benefits to your organization and infrastructure. From lower overhead management to security controls and provider support, utilizing resources from the cloud can increase your organization’s overall security posture and help you get ahead. Cloud computing and virtualization does not eliminate the risk your organization faces from threats, however, ensuring proper configuration and maintenance of virtual machines or cloud services will minimize your attack surface leading to a safer operation with minimal disruption to services.

A simple, yet very effective way to secure a network is through firewalls. When utilizing firewalls within a cloud network, this practice follows a similar style to traditional self-hosted and owned networks with the exception of customer access to the firewall(s). For example, customers using cloud networks would be provided with firewalls within the network but would be managed by the cloud provider. Direct access is not given to the customer since that would violate the isolation principle by potentially allowing a customer to make configuration changes, intentionally or unintentionally, to the firewall resulting in impact to service or lowered security.[4]

Virtual Private Cloud (VPC) networks allow an organization, or yourself, to establish any desired number of networks and subnetworks. These would be hosted by the cloud provider but managed by you or the organization. With segmentation being a minimum requirement within an IT department to establish further security control over a network, VPC networks allow for further expansion of your network while significantly reducing the maintenance, cooling power, and staffing that comes from owning multiple servers onsite.

The term Virtualization is defined in the CompTIA Network + Study Guide Exam N10-009 by Sybex glossary as; “Virtualization - The segmentation of processes on the shared resources of a server or cloud that allows processes to operate as if they had dedicated or physical resources.”[3] Simply put, virtualization is when an organization uses physical resources from a cloud provider carry out tasks for the overall benefit of the company whether it be for security, financial, or general efficiency.

Footnotes

References

[1] Lammle, T., & Buhagiar, J. (2024). Comptia Network+ Study Guide exam N10-009 (C. Crayton, Ed.). Wiley-Sybex.

[2] Chapple, M., & Seidl, D. (2021). Comptia Security+ Study Guide: Exam SY0-601 (N. H. Tanner, Ed.). Sybex. chapter 10 page 286

[3]Chapple, M., & Seidl, D. (2021). Comptia Security+ Study Guide: Exam SY0-601 (N. H. Tanner, Ed.). Sybex. page 307

[4] Chapple, M., & Seidl, D. (2021). Comptia Security+ Study Guide: Exam SY0-601 (N. H. Tanner, Ed.). Sybex. page 312

Lammle, T., & Buhagiar, J. (2024). Comptia Network+ Study Guide exam N10-009 (C. Crayton, Ed.). Wiley-Sybex.

Chapple, M., & Seidl, D. (2021). Comptia Security+ Study Guide: Exam SY0-601 (N. H. Tanner, Ed.). Sybex.