|
|
|
|
|
|
|
|
|
| |
|
Media Quote
"Configuresoft ECM tackles compliance issues for virtualized environments, from licensing to SOX."
- Joe Hernick
SW Licensing Woes In VMland

|
| |
|
|
|
|
Virtualization Compliance
Virtualization platforms such as VMware ESX server delivers compelling benefits to organizations by enabling server consolidation, power/space savings in datacenter. To effectively manage and secure virtual environments, IT operations need enterprise level visibility into the entire environment. Organizations need to ensure that the rapid deployment does not turn into uncontrolled creation of new virtual servers resulting in a virtual server sprawl. Virtualized environments need to demonstrate compliance with government, industry and vendor standards. Gartner estimates that by 2009, 60% of production VMs will be less secure than their physical counterparts. Thus, hardening of virtual platforms against emerging threats becomes an important requirement for IT operations. To take full advantage of virtualization, IT operations need to revisit and refine their existing IT processes. Configuration, change and compliance management processes need to take into account the dependencies between host and guests in a virtual environment.
The Solution
ECM for Virtualization helps organizations address the complexities associated with security and compliance in virtualized environments. ECM for Virtualization provides
visibility, control and management across the VMware infrastructure from a central console by extending VMware VirtualCenter with compliance capabilities. Using ECM for Virtualization, customers can understand the security posture to comply with VMware™ hardening guidelines and other applicable regulations such as PCI-DSS, Sarbanes-Oxley, GLBA, HIPAA and ISO. ECM for Virtualization enables organizations to enforce VM build policy and gain control over virtual server sprawl.

Virtual Security Posture Dashboard |

Top 10 Non-Compliant Virtual Environments |

Change Management Dashboard |
Key Features
- Virtualization Visibility
- Includes graphical indicators of non-compliance issues across entire virtual
environment. Dashboards provide a view of top 10 non compliant virtual environments, Host and Guest summaries, Virtual environment security
posture.
- Extend VMware VirtualCenter for Compliance
- By using the VirtualCenter Compliance plug-in, you can view compliance of your VMware environment from within VMware VirtualCenter and launch ECM in context.
- Security Hardening and Compliance Toolkits
- Provides out-of-the-box templates that address vendor and
virtualization best practices, regulatory mandates and security hardening guidelines such as:
- CIS benchmarks for VMware ESX server
- VMware hardening guidelines for VMware ESX server and Virtual Center.
- HIPAA
- FISMA
- GLBA
- Sarbanes-Oxley(404)
- DISA STIG
- NERC/FERC
- Reporting
- Out-of-the-box reporting on virtual environment change log, virtual Host and Guest summary, storage
allocation, network configuration and more.
- Guest/Host Relationship Correlation
- Supports management and
security compliance of each Guest, Host and the associated relationships across the entire virtualized landscape.
- Visibility
Into Dormant VMs
- Assesses the security posture of dormant VMs before they can compromise the integrity of the overall
infrastructure. By knowing the security posture of VMs before they went dormant will help you determine if they are vulnerable.
- License Management
- Provides a summary of license usage in virtual environments to aid with license management.
Key Benefits
- Secure Enterprise Visibility
- A single pane of glass to view entire ESX server deployments, enabling you to control your entire ESX infrastructure.
- Ensure Continuous Compliance
- Proven approach ensures that hosts and guests remain in a continuous state of compliance. Make compliance
part of daily operational processes.
- Understand Security Posture
- Authoritative guidance that
your security posture not only complies with vendor-specific hardening guidelines, but also with relevant regulatory mandates affecting your
organization.
- Enforce VM Build Policy
- Detect and remedy guests that violate build policy such as minimum OS
version.
- Control Virtual Sprawl
- Visually map the virtual infrastructure
and track the life cycle of virtual hosts and guests.
|
|
|
| | |
|