<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: virtualization]]></title>
    <link>http://securityratty.com/tag/virtualization</link>
    <description></description>
    <pubDate>Tue, 19 Aug 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The challenge of securing virtualization operations]]></title>
      <link>http://securityratty.com/article/9f000fa0b7a7a32adf10e294457b83e7</link>
      <guid>http://securityratty.com/article/9f000fa0b7a7a32adf10e294457b83e7</guid>
      <description><![CDATA[I have been very interested in virtualization security since early 2004 and it now seems like it has become a mainstream topic. Most of the focus however is on securing the technology of...]]></description>
      <content:encoded><![CDATA[I have been very interested in virtualization security since early 2004 and it now seems like it has become a mainstream topic. Most of the focus however is on securing the technology of virtualization (the hypervisor) and providing virtualized security (usually as virtual appliances). My focus nowadays is more on the operational impact of virtualized infrastructure and by extension the impact on security operations. After all, security controls (technology) are essential but without operational controls (people) they are not sufficient. So what is the operational impact of virtualization?]]></content:encoded>
      <pubDate>Mon, 01 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtualization security">virtualization security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/security operations">security operations</category>
      <category domain="http://securityratty.com/tag/operational impact">operational impact</category>
      <category domain="http://securityratty.com/tag/impact">impact</category>
      <category domain="http://securityratty.com/tag/security controls">security controls</category>
      <category domain="http://securityratty.com/tag/focus nowadays">focus nowadays</category>
      <category domain="http://securityratty.com/tag/focus">focus</category>
      <source url="http://www.networkworld.com/columnists/2008/090208-andreas.html?fsrc=rss-security">The challenge of securing virtualization operations</source>
    </item>
    <item>
      <title><![CDATA[How do you Manage Virtualization if you cant see Performance?]]></title>
      <link>http://securityratty.com/article/ed2ef4931f690c62b02f28e517c0aa0d</link>
      <guid>http://securityratty.com/article/ed2ef4931f690c62b02f28e517c0aa0d</guid>
      <description><![CDATA[NetIQ, which seemed to drop off the planet not long after being bought by Attachmate , is back with the results of a very interesting virtualization survey . Now, you know that you need to take all...]]></description>
      <content:encoded><![CDATA[<p>NetIQ, which seemed to drop off the planet not long after being <a href="http://www.itjungle.com/tfh/tfh071706-story08.html">bought by Attachmate</a>, is back with the results of a very interesting <a href="http://tarrysingh.blogspot.com/2008/08/netiq-survery-virtualization-initiative.html">virtualization survey</a>. Now, you know that you need to take all surveys with a big grain of salt (e.g., the majority of respondents to this one were less than 10% virtualized), but it&#8217;s still good to take temperatures whenever possible. </p>
<p>The numbers we found interesting: </p>
<p>- only 21% currently deploying virtualization have any kind of systems management solutions for their virtual infrastructure </p>
<p>- about 27% are managing performance/ability of virtual systems with same tools they use for physical servers (Nothing wrong with that as long as they&#8217;re seeing what they need to see but&#8230;)</p>
<p>- 40 percent of those surveyed do not report the performance of their virtualized applications, hardware, <a href="http://virtualization.com/news/2008/08/26/netiq-survey-results-reflect-lack-of-virtualization-management-basics/">operating systems, or their virtual machines in any measureable</a> way (which rather undercuts the whole point)</p>
<p>Get the full results <a href="http://download.netiq.com/Library/Misc/VirtualizationSurveyAnalysis-Aug2008.pdf">here</a>.</p>
]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 21:15:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/systems management solutions">systems management solutions</category>
      <category domain="http://securityratty.com/tag/virtual systems">virtual systems</category>
      <category domain="http://securityratty.com/tag/virtualization survey">virtualization survey</category>
      <category domain="http://securityratty.com/tag/virtual machines">virtual machines</category>
      <category domain="http://securityratty.com/tag/physical servers">physical servers</category>
      <category domain="http://securityratty.com/tag/virtual infrastructure">virtual infrastructure</category>
      <category domain="http://securityratty.com/tag/performance">performance</category>
      <source url="http://blog.sciencelogic.com/how-do-you-manage-virtualization-if-you-cant-see-performance/08/2008">How do you Manage Virtualization if you cant see Performance?</source>
    </item>
    <item>
      <title><![CDATA[HP Hires 140,000 to Get Rid of Your Job]]></title>
      <link>http://securityratty.com/article/1b40a911042fda84f13e9dbc287cf501</link>
      <guid>http://securityratty.com/article/1b40a911042fda84f13e9dbc287cf501</guid>
      <description><![CDATA[HP completed its $13.25 billion acquisition of EDS today
Can HP-EDS put its money where its mouth is? EDS profit margin, pre-acquisition, was under 6%. The former EDS CEO, now heading the combined...]]></description>
      <content:encoded><![CDATA[<p>HP completed its $13.25 billion acquisition of EDS today. </p>
<p>Can HP-EDS put its money where its mouth is? EDS profit margin, pre-acquisition, was under 6%. The former EDS CEO, now heading the combined outsourcing unit, expects to leverage HP automation tools to cut costs and improve that margin.</p>
<p>But Rod Bourgeois, an analyst at Sanford Bernstein says, &#8220;It&#8217;s not like HP has automation tools that weren&#8217;t at <a href="http://online.wsj.com/article/SB121971997812971951.html?mod=hps_us_whats_news">EDS&#8217;s disposal before</a>.&#8221;</p>
<p>But this brings up a good point. EDS and 140,000 new bodies notwithstanding, HP seems to be positioning itself to do a big <a href="http://blogs.wsj.com/biztech/2008/08/26/the-key-to-h-p-eds-automation/?mod=djemTECH">automation push in the marketplace</a>. </p>
<p><a href="http://www.infoworld.com/article/08/05/13/What-does-the-HP-EDS-deal-really-mean_1.html?source=fssr">Of course this makes sense</a> &#8211; we&#8217;ve talked before about what a critical role automation is going to have in managing the rapidly evolving &#8220;dynamic&#8221; data center. Technologies like virtualization and cloud computing needs are pushing out the limits of real-time resources management in the data center; management tools must perform faster, integrate with more solutions across the spectrum of IT infrastructure and be smart enough to do much of this on their own.</p>
]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 09:47:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/eds">eds</category>
      <category domain="http://securityratty.com/tag/hp-eds">hp-eds</category>
      <category domain="http://securityratty.com/tag/eds ceo">eds ceo</category>
      <category domain="http://securityratty.com/tag/eds profit margin">eds profit margin</category>
      <category domain="http://securityratty.com/tag/margin">margin</category>
      <category domain="http://securityratty.com/tag/dynamic data center">dynamic data center</category>
      <category domain="http://securityratty.com/tag/data center">data center</category>
      <category domain="http://securityratty.com/tag/automation tools">automation tools</category>
      <category domain="http://securityratty.com/tag/real-time resources management">real-time resources management</category>
      <source url="http://blog.sciencelogic.com/hp-hires-140000-to-get-rid-of-your-job/08/2008">HP Hires 140,000 to Get Rid of Your Job</source>
    </item>
    <item>
      <title><![CDATA[Fun Reading on Security - 7]]></title>
      <link>http://securityratty.com/article/c474f15d19ef80949f385cbe7b510b79</link>
      <guid>http://securityratty.com/article/c474f15d19ef80949f385cbe7b510b79</guid>
      <description><![CDATA[Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot; Fun Reading on Security .&quot; Here is an issue #7, dated August 27th, 2008
Sad,...]]></description>
      <content:encoded><![CDATA[<p>Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot;<a href="http://chuvakin.blogspot.com/search/label/reading">Fun Reading on Security</a>.&quot; Here is an issue #7, dated August 27th, 2008.</p>  <ol>   <li>Sad, but VERY insightful story of Alan Shimmel getting 0wned (<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/08/im-back.html">1</a>,<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/08/more-frustratio.html">2</a>,<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/08/our-web-infrast.html">3</a>,<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/08/why-google-is-n.html">4</a>, others on his blog) </li>    <li>A very good essay on security industry/market/community &quot;<a href="http://blog.trailofbits.com/2008/07/24/evolution-is-punctuated-equilibria/">Evolution is Punctuated Equilibria</a>&quot; <em>(&quot;Right now, Internet security is due for another period of rapid change.&quot;)</em> </li>    <li>As I like to say, most everybody in out industry is confused about risk (myself included, in fact) - here is some nice reading about the subject: &quot;<a href="http://layer8.itsecuritygeek.com/layer8/quant-love/">Quant love&quot;</a>, &quot;<a href="http://risktical.com/2008/07/31/what-is-risk/">What is Risk?</a>&quot; (&quot;<em>The probability of a threat overcoming security controls resistance to exploit a vulnerability that results in a loss.</em>&quot;) While you are at it, check <a href="http://risktical.com/2008/08/24/risk-and-cvss-post-1/">this blurb</a> about risk and <a href="http://www.first.org/cvss/">CVSS</a> (BTW, <a href="http://www.first.org/cvss/">CVSS</a> is about &quot;V&quot; - vulnerability, not &quot;R&quot; for risk!)</li>    <li>Solid gold on &quot;running IT as business&quot; (and where it hits the wall) - <a href="http://taosecurity.blogspot.com/2008/08/limits-of-running-it-like-business.html">Richard</a>, <a href="http://www.cio.com/article/print/335813">the original CIO.com piece</a>&#160;<em>(&quot;If you've tried managing an internal IT department as a bona fide business you already know that you can't take that very far, for the obvious reason that your IT department isn't a business.&quot;)</em> </li>    <li>More fun stuff from Richard <a href="http://taosecurity.blogspot.com/2008/07/counterintelligence-worse-than-security.html">on insiders and why NOT look for them</a> (sadly, same logic applies to not looking for owned boxes in your environment...). </li>    <li>Analyst firms <a href="http://www.forrester.com/Research/Document/Excerpt/0,7211,46811,00.html">shocking discovery</a>: wireless MAY have security issues (I guess count it as humor...)</li>    <li>Fun read: &quot;<a href="http://onsaas.net/2008/08/23/challenges-of-enterprise-cloud-computing/">Challenges of Enterprise Cloud Computing</a>&quot; (<em>&quot;By moving the data into the cloud, enterprise, for now, will lose some capabilities to govern their own data set.&quot;</em>) </li>    <li><a href="http://searchnetworking.techtarget.com/news/article/0,289142,sid7_gci1326271,00.html">Raffy on visualization</a>. (<em>&quot;One of the dangerous things is if you don't understand the log file itself, don't assume you'll understand the visualization of it or even generate a visualization that makes sense&quot;</em>) Amen to that! BTW, Raffy's book is finally <a href="http://www.amazon.com/gp/product/0321510100/ref=cm_cr_pr_product_top">out.</a> </li>    <li>Compliance and checkbox mentality: fun pickup from <a href="http://chuvakin.blogspot.com/2008/08/few-more-words-on-dlp-and-compliance.html">my original &quot;DLP and Compliance&quot; post</a> - <a href="http://securosis.com/2008/08/18/dont-sell-compliance-if-it-isnt-a-checkbox/">Rich</a> and <a href="http://channelmarker.blogs.techtarget.com/2008/08/19/794/">TechTarget</a>. Good stuff! (&quot;<a href="http://securosis.com/2008/08/18/dont-sell-compliance-if-it-isnt-a-checkbox/"><em>Don&#8217;t Sell &#8216;Compliance&#8217; If It Isn&#8217;t A Checkbox </em></a>&quot;) </li>    <li>RedHat is <a href="http://www.redhat.com/archives/fedora-announce-list/2008-August/msg00012.html">nicely 0wned</a> (<a href="http://isc.sans.org/diary.html?storyid=4921">more info</a>)</li>    <li><a href="http://blog.wired.com/27bstroke6/2008/08/revealed-the-in.html">BGP hole</a> to dwarf the DNS hole?</li>    <li>Chris continues the virtualization and PCI DSS theme <a href="http://rationalsecurity.typepad.com/blog/2008/08/virtualized-inf.html">here</a>. The jury is still out on this one, even though the common sense approach (that virtualization is OK in regards to PCI) will probably win.</li>    <li>NEWS FLASH! <a href="http://blog.modernmechanix.com/2008/03/31/the-national-data-center-and-personal-privacy/">Privacy dies</a>. The date of death? 1967. While <a href="http://blog.modernmechanix.com/2008/03/31/the-national-data-center-and-personal-privacy/">reading it</a>, think just how visionary some folks are...</li>    <li>Finally, just for laughs: <a href="http://www.wikihow.com/Spin-Bad-News">How to Spin Bad News</a> </li> </ol>  <p>Enjoy!</p>  <p>BTW, I am saving some fun reading for dedicated posts soon :-)</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=jdwxUK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=jdwxUK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=PB8ogK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=PB8ogK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=YLH24K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=YLH24K" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/376393795" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 06:56:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/security controls resistance">security controls resistance</category>
      <category domain="http://securityratty.com/tag/stuff">stuff</category>
      <category domain="http://securityratty.com/tag/fun stuff">fun stuff</category>
      <category domain="http://securityratty.com/tag/security issues">security issues</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/bona fide business">bona fide business</category>
      <category domain="http://securityratty.com/tag/fun pickup">fun pickup</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/376393795/fun-reading-on-security-7.html">Fun Reading on Security - 7</source>
    </item>
    <item>
      <title><![CDATA[Securing virtualized data centers]]></title>
      <link>http://securityratty.com/article/cd1711580306bb2b00fcd941d29e9473</link>
      <guid>http://securityratty.com/article/cd1711580306bb2b00fcd941d29e9473</guid>
      <description><![CDATA[While server virtualization increases operational efficiencies, management flexibility and reduces total cost of ownership, it can also increase security...]]></description>
      <content:encoded><![CDATA[While server virtualization increases operational efficiencies, management flexibility and reduces total cost of ownership, it can also increase security risks.]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/reduces total cost">reduces total cost</category>
      <category domain="http://securityratty.com/tag/increase security risks">increase security risks</category>
      <category domain="http://securityratty.com/tag/management flexibility">management flexibility</category>
      <category domain="http://securityratty.com/tag/ownership">ownership</category>
      <source url="http://www.networkworld.com/news/tech/2008/082708-tech-update.html?fsrc=rss-security">Securing virtualized data centers</source>
    </item>
    <item>
      <title><![CDATA[Run Through PCI DSS 1.2 Changes]]></title>
      <link>http://securityratty.com/article/ce0e02f57e234e1b64d186272da31186</link>
      <guid>http://securityratty.com/article/ce0e02f57e234e1b64d186272da31186</guid>
      <description><![CDATA[Finally, I found time to read PCI DSS 1.2. change doc. So
Good news: router is now officially a firewall (it has been for a while, but many people are still stuck in &quot;security device&quot; vs &quot;network...]]></description>
      <content:encoded><![CDATA[<p>Finally, I found time to read PCI DSS 1.2. change doc. So:</p>  <ul>   <li>Good news: router is now officially a firewall (it has been for a while, but many people are still stuck in &quot;security device&quot; vs &quot;network device&quot; cloud) - see Req 1 </li>    <li>From the &quot;WTH dept&quot;: anti-virus is a MUST on <strong>ALL</strong> platforms - Req 5. Please ship me some of the stuff they are smoking; I want it! BTW, I am <a href="http://www.govcert.nl/symposium/index.html">going to Amsterdam soon</a> :-) </li>    <li>WAF or code review for web application security is still a stupid &quot;OR&quot; - Req 6.6. OMG, please, <a href="http://www.tssci-security.com/archives/2008/06/27/week-of-war-on-wafs-day-5-final-thoughts/">software security folks</a>, teach them the truth.</li>    <li>Can we kill &quot;plain text passwords&quot; once and for all? Req 8 tries to achieve that noble goal (good thing!) </li>    <li>Visit your offsite data storage - good (if costly) idea - added to Req 9. Requirements to secure electronic AND&#160; paper media&#160; are solid too.</li>    <li>Love it, love it! Req 10 explains that logs needs to be actually available: 'three months of audit trail history must be &#8220;<strong>immediately available for analysis</strong>&#8221; or <strong>quickly accessible'</strong> (bye-bye, silly log dumps...)</li>    <li>Some vulnerability stuff clarified in Req 11, mostly about ASVs and pentesting.</li>    <li>Scope of security policy is expanded to &quot;employee-facing technologies&quot; (what a term!) - Req 12</li>    <li>All over: more references to wireless&#160; (WEP, access points, hidden SSIDs, etc) - indeed, recent data losses are often due to insecure wireless.</li> </ul>  <p>Overall, a minor change that, sadly, doesn't touch a few KEY areas, such as virtualization, for one.</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=oED2TK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=oED2TK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=pUb9XK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=pUb9XK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bX5cGK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bX5cGK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/375460383" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 07:38:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/req">req</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/offsite data storage">offsite data storage</category>
      <category domain="http://securityratty.com/tag/insecure wireless">insecure wireless</category>
      <category domain="http://securityratty.com/tag/audit trail history">audit trail history</category>
      <category domain="http://securityratty.com/tag/silly log dumps">silly log dumps</category>
      <category domain="http://securityratty.com/tag/wireless">wireless</category>
      <category domain="http://securityratty.com/tag/plain text passwords">plain text passwords</category>
      <category domain="http://securityratty.com/tag/vulnerability stuff">vulnerability stuff</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/375460383/run-through-pci-dss-12-changes.html">Run Through PCI DSS 1.2 Changes</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-08-25 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/971b61f5d2ba103bfbf9e50241696a4d</link>
      <guid>http://securityratty.com/article/971b61f5d2ba103bfbf9e50241696a4d</guid>
      <description><![CDATA[InternetNews Realtime IT News - Motorola Buys AirDefense
Virtualization Monitoring | Virtualization Information Q: Often Splunk is associated with being just security tool. Why do IT server...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.internetnews.com/security/article.php/3762106/Motorola+Buys+AirDefense.htm">InternetNews Realtime IT News - Motorola Buys AirDefense</a></li>
<li><a href="http://virtualizationinformation.com/?page_id=207">Virtualization Monitoring | Virtualization Information</a><br/>
Q: Often Splunk is associated with being just security tool. Why do IT server administrators want this for their virtualization platform?

A: It is funny that Splunk has that image!  Application and server availability is actually our predominant use case, with security and compliance a good way behind.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/374902986" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/virtualization platform">virtualization platform</category>
      <category domain="http://securityratty.com/tag/virtualization information">virtualization information</category>
      <category domain="http://securityratty.com/tag/motorola buys airdefense">motorola buys airdefense</category>
      <category domain="http://securityratty.com/tag/security tool">security tool</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/server availability">server availability</category>
      <category domain="http://securityratty.com/tag/splunk">splunk</category>
      <category domain="http://securityratty.com/tag/server administrators">server administrators</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/374902986/anton18">Links for 2008-08-25 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Antivirus policies remain contradictory for VMware]]></title>
      <link>http://securityratty.com/article/765cf4b04f702c38f8f3032c8edec6bb</link>
      <guid>http://securityratty.com/article/765cf4b04f702c38f8f3032c8edec6bb</guid>
      <description><![CDATA[Have you read your security policy today? Does it take virtualization into...]]></description>
      <content:encoded><![CDATA[Have you read your security policy today? Does it take virtualization into account?<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=5821?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=5821?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Sun, 24 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security policy">security policy</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <source url="http://www.networkworld.com/news/2008/082508-antivirus-policies-remain-contradictory-for.html?fsrc=rss-security">Antivirus policies remain contradictory for VMware</source>
    </item>
    <item>
      <title><![CDATA[ScienceLogics 5-Year Anniversary]]></title>
      <link>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</link>
      <guid>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</guid>
      <description><![CDATA[August 2003. The largest blackout in U.S. history darkens the Northeast and Midwest, the Blaster worm has been unleashed and Madonna and Britney create a stir at the 2003 MTV Music Video Awards . In...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="164" alt="B-day Cake" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/b-day-cake1.jpg" width="244" align="left" border="0"> August 2003. The largest <a href="http://blogs.wsj.com/biztech/2008/08/13/celebrating-the-anniversary-of-the-big-blackout/?mod=djemTECH" target="_blank">blackout</a> in U.S. history darkens the Northeast and Midwest, the <a href="http://news.cnet.com/2010-1001-5117862.html" target="_blank">Blaster worm</a> has been unleashed and Madonna and Britney create a stir at the <a href="http://en.wikipedia.org/wiki/2003_MTV_Video_Music_Awards" target="_blank">2003 MTV Music Video Awards</a>. In the midst of this <a href="http://www.grid.unep.ch/product/publication/download/ew_heat_wave.en.pdf" target="_blank">hot summer</a> madness, ScienceLogic was founded.
<p>To kick off our celebration of our first five years, we asked <a href="http://www.sciencelogic.com/leadership.htm" target="_blank">ScienceLogic founders</a> Dave Link, Richard Chart and Chris Cordray for their thoughts and memories on events leading to today’s milestone. How and why did they set out on this venture? What happened along the way – expected and unexpected? Why were they successful in times when other new (and established) businesses have come and <a href="http://en.wikipedia.org/wiki/Category:2003_disestablishments" target="_blank">gone</a>?
<p><b>How did you three put together this team?</b>
<p>We all worked together at a large Managed Service Provider for a couple of years before leaving to start ScienceLogic, so we all knew each other and knew our collective strengths. More importantly, each of us had worked with network management tools on some level (sales and marketing, engineering and product development), and knew first-hand all of the customer pain points, from every perspective. So we left and began rapidly figuring out how to build a better network management solution based upon our real world operational experience..
<p><strong>Dave:</strong> One interesting aspect is that our areas of expertise don’t overlap, which has contributed to our success. Chris is excellent with developing the product front-end and interface, Richard handled the backend architecture and engineering and I focused on the technical business side of sales and marketing. Our roles have been to build a product that works well and that provides real value to operations teams that experience the same day to day frustrations that we felt.<b></b>
<p><b>Whose idea was it to start the company?</b>
<p><strong>Dave:</strong> It was really a collective effort. We were all passionate about “getting it right” and not just starting a company. We knew the industry need and between us, we had the knowledge and skill sets to address all of the right aspects of developing a product and a building a business around it.
<p><b>What process did you go through to get started?</b>
<p><strong>Richard:</strong> From the beginning we knew the type of solution the market needed and we knew that we wanted to build it as an appliance. From different vantage points, we had each experienced the effects of long, difficult and expensive installations that still exist with traditional network tools. Every install has unique variations: there are always different server types, varying hardware and software versions, different patches installed, and on and on. Every installation was time consuming and unpredictable. We knew that an appliance model would address all of these variables and save a lot of time on how quickly customers could achieve immediate value.
<p>The harder decisions were around actually starting the business, assessing the market and of course determining the product pricing.
<p><b>EM7 completely flips the traditional model of complex, lengthy and expensive deployments. How did you convince others that the EM7 Meta-Appliance product was valid?</b>
<p><strong>Dave:</strong> Yes, EM7 totally disrupts the traditional model for network management. While others take a narrow approach, we intentionally designed EM7 to focus on the broad problem – managing the data center. How do you cover a variety of technologies and make sure they work seamlessly together? The vision was to make it easier, not harder, for customers.
<p><strong>Chris:</strong> I have to give it to Dave – very early on, he realized the power of a demo. If Dave could get in front of someone, he’d make them a believer. He’d use the Peter Falk/Columbo technique of “let me show you one more thing.” It was very effective. It’s getting easier, but even today people sometimes have to see EM7 in action before they become believers.
<p><b>Can you describe the early days of running a new business?</b>
<p><strong>Dave:</strong> ScienceLogic is a classic case of entrepreneurship. For the first year we worked out of our basements. We kept the costs low in every conceivable way and spent the first year developing the product before we even made a sale.
<p><strong>Chris:</strong> We stayed at lots of odd places when we were on the road, took cheap flights with multiple layovers and purchased lots of our first test equipment on eBay. This was during the dot-com bust so there was lots of equipment for sale on eBay, really cheap!
<p><strong>Richard:</strong> The amount of equipment I had in my house was absolutely crazy. Back then, servers were huge – I had a Cisco 6509 Catalyst, a Compaq Proliant DL380, Brocade switch, IBM Netfinity 4500R, and tons of other machines.
<p><strong>Chris:</strong> I had to install a new circuit box at home because I was blowing breakers. I remember when that 6509 crashed, we revived it and it died again. The second death was final.
<p><b>So you started in your houses – what was your first office space?</b>
<p><strong>Dave:</strong> My friend, the CEO at Ernst &amp; Young Technology had a few extra cubes and a data center in their office that they graciously allowed us to use. Their help was an important step in helping us really formalize the business. We started doing well and adding people, but ironically, their company was downsizing. Before long, many of their original YET people were gone and the ScienceLogic team kept growing in to the open cubes.
<p>Our first leased space was converted warehouse space in Chantilly, VA that once housed an internet radio station. It was cool – it had a large salt water fish tank, a loft, a spiral staircase and a Star Trek door that retracted into the walls with the customary lights and “whooshing” sound.
<p>We outgrew the Chantilly space, leading to our current office in Reston, VA.
<p><b>Who was the first ScienceLogic customer?</b>
<p>Our first paying customer was <a href="http://martinspoint.com/" target="_blank">Martins Point Health Care</a>. We deployed there in July 2004 and are pleased to say they continue to be a ScienceLogic customer. Other early (and still) EM7 <a href="http://www.sciencelogic.com/customers.htm" target="_blank">customers</a> include Navy Knowledge Online and the Department of Transportation. Nearly all of our customers are still actively using EM7 and renewing their maintenance.
<p><b>Where do you see the company in the next 5, 10 or 15 years?</b>
<p>Well, our revenue has doubled year-over-year in each of the last three years, so of course we’d like to continue to grow like that or even faster. In five years we’ve gone from three founders to the point where Dave does not know everyone’s fondest childhood memory. We’ll continue to scale our growth to cover the demands of our growing customer base.
<p><b>Where do you see the industry going over the coming years?</b>
<p><strong>Chris:</strong> IT is always moving and gaining in complexity, so network management is also becoming more complicated. There’s increasing diversity, new standards, virtualization and cloud computing. All of these are today’s technologies. Customers have a mix of the old and the new, so EM7 has to accommodate and support both.
<p><strong>Richard:</strong> Each generation of products has a new set of ways to monitor, but the “old” doesn’t go away. Even when a new, hot technology comes along, the old technologies still need to be supported. We work to ensure EM7 keeps up with both.
<p><strong>Dave:</strong> After five years we’re just hitting our stride and we’re just now reaching the tipping point in awareness of ScienceLogic and EM7. We’re all still passionate about the product and as Chris and Rich said, there’s still a lot do. We’ll continue disrupting the market with EM7. Our vision hasn’t changed, and with the increasing levels of automation that customers demand, the market needs are greater than ever. Our future is as bright, or brighter, than ever and we’ll continue to be looking for smart ways to automate traditionally manual IT Operations processes.
<p><b>What’s your advice for someone interested in starting their own business?</b>
<p><strong>Chris:</strong> Be passionate. That’s what has gotten me through the tough times. I didn’t really appreciate this thought when I heard others say it before. But it’s very true.
<p><strong>Richard:</strong> I agree. We met and talked with lots of people who told us, “That’s been done before.” But we kept going because we truly believed in what we were doing and we knew that while our approach was different, that it would be successful.
<p><strong>Richard:</strong> Be fearless. You can’t be too nervous and you need to be able to expect and handle the stress because it will be there. You have to learn to accept the stressful times as a necessary part of the process of starting out on your own.
<p><strong>Dave:</strong> Know your niche from the beginning and give potential customers a compelling reason to trust you and really benefit from your solution. You have to know the problem, see the gap and have a clear and consistent vision of how to solve the problem. Then you have to execute. If you don’t build your team with “doers” you won’t make it.
<p><strong>Chris:</strong> It helps to have friends. ScienceLogic was built on friendships and relationships, starting with the three of us. If you look at our team, most of our hires are referrals – people who developed and maintained great connections with other great people throughout their careers. Maintain your connections and keep in touch with your network of friends.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 18:39:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7 completely flips">em7 completely flips</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/network management tools">network management tools</category>
      <category domain="http://securityratty.com/tag/em7 meta-appliance product">em7 meta-appliance product</category>
      <category domain="http://securityratty.com/tag/sciencelogic team">sciencelogic team</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/front">front</category>
      <category domain="http://securityratty.com/tag/product front-end">product front-end</category>
      <source url="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008">ScienceLogics 5-Year Anniversary</source>
    </item>
    <item>
      <title><![CDATA[Virtualizing network security]]></title>
      <link>http://securityratty.com/article/05a3e01f3ecfcdb36f93fa5c22e38722</link>
      <guid>http://securityratty.com/article/05a3e01f3ecfcdb36f93fa5c22e38722</guid>
      <description><![CDATA[Enterprise network managers are looking to virtualize more data center resources, but they hesitate when it comes to security. They want the resource sharing and hardware consolidation that...]]></description>
      <content:encoded><![CDATA[Enterprise network managers are looking to virtualize more data center resources, but they hesitate when it comes to security. They want the resource sharing and hardware consolidation that virtualization offers but aren't willing to risk compromising security.]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/enterprise network managers">enterprise network managers</category>
      <category domain="http://securityratty.com/tag/data center resources">data center resources</category>
      <category domain="http://securityratty.com/tag/virtualization offers">virtualization offers</category>
      <category domain="http://securityratty.com/tag/hardware consolidation">hardware consolidation</category>
      <category domain="http://securityratty.com/tag/resource">resource</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <source url="http://www.networkworld.com/news/tech/2008/082008-tech-update.html?fsrc=rss-security">Virtualizing network security</source>
    </item>
  </channel>
</rss>
