vCloud

 View Only
  • 1.  How to do a basic vSphere Audit

    Posted Jan 12, 2015 03:52 PM

    Does anyone have a list of things to check or a guide as to all the things I should check when doing my own internal audit of a vSphere environment for the purposes of checking security?



  • 2.  RE: How to do a basic vSphere Audit

    Posted Jan 12, 2015 05:54 PM

    You can start using the free Compliance Checker for vSphere: Free Compliance Checker for VMware vSphere | United States

    Another option, but not free, is the product from Nessus: New Nessus VMware vSphere/vCenter Audits Now Available | Tenable Network Security



  • 3.  RE: How to do a basic vSphere Audit

    Posted Jan 12, 2015 06:19 PM

    Ok great.  These tools look good.  Is there any such thing as just a word doc or a pdf or a website that lists all the things and areas in your enviornment you need to check for SOX, HIPPA or PCI to pass an audit?



  • 4.  RE: How to do a basic vSphere Audit



  • 5.  RE: How to do a basic vSphere Audit
    Best Answer

    Posted Jan 15, 2015 12:31 PM

    Hello,

    THe closest set of tools to your needs are from VMware (vCM plugins and standalone packages, also look for something to be demoed at RSA Conference this year), HyTrust, and Catbird. There are some standalone tools that will give you security auditing of your Virtual environment from William Lam (but it is limited), myself (but used by my consultancy), and a few others. It is actually a fairly hard problem to solve.

    vSphere when it comes to PCI, HIPAA is not your only worry, you need to worry about networking, the VMs, segmentation, storage, etc. The best thing I can suggest is to first define your scope of VMs and determine what touches them directly and indirectly. Compliance is all about scope of the audit. No one audits the entire environment for PCI, but a part of it for example. Else you would need to audit the entire datacenter as it is all usually interconnected in some way. So how do you limit scope? By segregating PCI and HIPAA workloads from one another or by limiting management systems or other systems peripheral to PCI and HIPAA from PCI and HIPAA systems.

    Best regards,
    Edward L. Haletky
    VMware Communities User Moderator, VMware vExpert 2009, 2010, 2011,2012,2013,2014

    Author of the books 'VMWare ESX and ESXi in the Enterprise: Planning Deployment Virtualization Servers', Copyright 2011 Pearson Education. 'VMware vSphere and Virtual Infrastructure Security: Securing the Virtual Environment', Copyright 2009 Pearson Education.

    Virtualization and Cloud Security Analyst: The Virtualization Practice, LLC -- vSphere Upgrade Saga -- Virtualization Security Round Table Podcast



  • 6.  RE: How to do a basic vSphere Audit

    Posted Jan 15, 2015 01:55 PM

    ok thanks again