Will you sit behind the wheel and
help drive physical security
standards in the virtualized world?
People have been asking me lately about physical security standards that will come into play with virtualized networks and whether or not there will be something specifically developed. The questions usually result in extended discussions surrounding the challenges of using hardware for a solution whose makeup of components may switch on an hourly basis depending on usage.
These boxes may be in different parts of the world and have potentially all sorts of sensitive information on them-Personal Medical Information, Financial Details, Work, job and salary histories, and HR Data including details on family members including children are just a few to start with. The risk profiles that a given virtual system may face are quite high-so how to address this? Guaranteeing security on these platforms will be a challenge and one that has been met with spotty success at present. Verified and auditable controls applied to these platform components will be the challenge.

While how this challenge is addressed is important, who will address it is likewise crucial? A quick look at the history of security will identify a host of players in this space; Standards Development Organizations (SDO’s), Government Organizations, Industry Verticals (Payment Card, Medical Information, etc.). With current trends, governments (at least some in the US and Europe) will surely push some sort of standards and with government involvement will come justifiable skepticism with the idea of really keeping the information protected (governments have been exposed quite a bit lately in this area in case you have been living on the moon). The industry and associated business verticals will surely have input as will risks exposed in early technology adopters when criminals and security researchers find cracks in the armor.
The last major players are the International Standards Organizations or SDO’s. I think that some of these are actually best positioned to drive standards-ironic right? In a world where everyone likes to set rigid standards and issue directives, some of these standards bodies are actually quite elastic in their makeup, consisting of industry and vertical members, governmental representations, academics involved in cutting edge research and study, and individual contributors. This flexibility allows an approach which facilitates adoption and avoids some of the pitfalls or other players in the area of standards.
My hope is that standards organizations will take the lead and quickly work towards physical and other security standards development in virtualized systems so that we have security baked in to the process early, giving us the best chance to minimize past errors in technology development when it involves security. In a few days, I will be getting together with some like-minded people from around the world with a view to providing a bit of sweat equity and trying to get one of these activities off the ground. For security practitioners reading this far, I would like to challenge you to take part in some of these activities. Jump in and take part, provide some thoughtful input, and I promise it will be time well spent.
Consulting: Need independent analysis or security support? See AI & Cybersecurity Consulting.
