FierceFinanceFierceFinanceITFierceCompliance IT   FierceCIO

Virtualization raises compliance issues

Tools
Tags
Virtualization
Virtual Machine
Virtual Environment
Production Applications
compliance
sarbox

Virtualization has been one of those trends that generates a lot of press--as it should. It's revolutionary. Virtualization notes the number of in-production applications running on virtualized systems will grow to between 45 percent and 60 percent of total deployments over the next two years, up from 15 percent now. Cost, of course, is the main driver. But the compliance aspects of virtualization are rarely discussed. Gartner finds that 60 percent of production virtual machines will be less secure than their physical counterparts through 2009. Virtualization notes: "The virtual environment...poses huge new compliance challenges, especially in auditing. How can an organization know if a virtual machine is compliant if it no longer exists? How do you track change history for auditors in a virtual world? Certainly these issues are now coming to the fore..." The PCI Standards Council is starting to grapple with this. We'll see if other advisory bodies, such as COSO, will address the issue.  

For more:
- here's the Virtualization article

Related Article:
ALSO NOTED: Does server virtualization pass the Sarbox smell test?

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.

More information about formatting options

What is 65 + 25?
To combat spam, please solve the math question above.