This is cache of http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/332018087/issue-that-virtually-everybody-and.html. Cache is the snapshot of article that we took when we index feed.
To see original page click here.
We are not affiliated with the authors of this article and not responsible for its content.
Issue That Virtually Everybody and Their Dog Is Confused About
2008-07-10 12:34:00 by Dr Anton Chuvakin in Anton Chuvakin Blog -
 
Here is an issue that everybody and their dog (and, likely, their dog's fleas :-)) is confused about:

What does PCI DSS Requirement 2.2.1 ("Implement only one primary function
per server (for example, web servers, database servers, and DNS should
be implemented on separate servers)") mean in virtualized environments?

Is it "one function per VM instance" or "one function per physical server?"

I've heard reports of QSA interpreting it either way, which means that millions of dollars of IT investments might be at stake.

Here are some arguments that I've heard about:
  • "VM instance is NOT a server" - thus physical separation is required.
  • "VM IS a different machine, might be different OS, etc" - thus it IS sufficient separation.
  • "VM is like a VLAN" - thus VM separation IS adequate separation. Then again: some say VLANs are not sufficient separation either.
I hereby call upon the unholy wisdom of Hoff to answer this little bugger...
 
 
 
 
 
 
SecurityRatty FAQ
Sergey Zarubin, 31yo
CISSP, CCSP
Moscow, Russia