We are well aware that virtualization has been widely implemented, however, there are questions regarding adequate considerations for security threats, known or perceived. It appears that many organizations rest on superior security at the physical layer for a secure virtual layer. This is due in part to an organization that is not aware of the risks associated specifically with the virtual layer or individuals that lack the knowledge to implement adequate security measures. This course changes everything.
This course covers all known and many perceived risks, demonstrates how to hack some of those risks and covers the best hardening practices known today. It covers many technologies related to the VMware vCloud Suite so that you know what you can and cannot do with the software as well as what needs to be added to your security posture to ensure a secure private cloud!
Technology:
vCloud Suite 5.5, vSphere 5.5, vCAC 5.5, vCOps 5.5, vCloud Networking and Security 5.5. All previous 5.x versions discussed.
Prerequisites
Network+ Certification or Equivalent Knowledge, Two Years’ Experience with Microsoft or Linux Servers, Basic Virtualization/Cloud Knowledge
Audience
Security Administrators and Engineers, Pen Testers, Virtualization/Cloud Administrators, and Engineers, System Engineers and Administrators
Course duration
5 days
Why Attend this Course
- Learn the latest technologies used to secure the vSphere and Private Cloud Infrastructure.
- The risks to a virtual datacenter are higher than most organizations realize, be prepared to mitigate those risks.
- Become a leader in the industry by staying on top of the security issues related to the private cloud.
- We cover the best third party solutions related to virtualization and the private cloud.
- This course will teach you how to test some of these known risks.
- Our team of developers have worked in the security field for many years, they pioneered today’s designs for a secure virtual infrastructure and wrote the first course on virtual security, they have tried and true best practices throughout this course.
- Take the VM’s home with you for additional work after class!
- 50% of your time will be hands on.
Course outline
Chapter 1 – Course Introduction
Chapter 2 – Virtualization and Cloud Overview
1. Overview of Virtualization
2. Overview of Cloud Technologies
a. Functional Requirements
Chapter 3 – Developing a vSphere Private Cloud Security Posture
4. Seven Step Approach to a Desired Security Posture
6. Deep Dive into vSphere Risks
f. vCloud – Related to Private Cloud Risks
Chapter 4 – vSphere Native Controls
1. ESXi Secure Architecture/ul>
2. Virtual Machines Secure Architecture
a. Virtual Machine Hardware
iii. Clones and Templates
iv. Roles and Permissions
3. Host and Cluster Native Controls
a. VMKernel Preventative Controls
b. vSphere 5.x Preventative Controls
c. ESXi File Systems Structure
4. vCloud Networking and Security
e. vCloud Ecosystem Framework
5. vCenter Native Controls
c. Distributed Resource Scheduler
d. vSphere Data Protection
f. Disaster Recovery Options
Chapter 5 – vNetwork Native Controls
1. vSwitch Native Controls
2. DvSwitch Native Controls
Chapter 6 – vStorage Security
1. Understanding Storage within the Virtual Architecture
a. Storage Capabilities based on Versions
d. All Paths Down and Permanent Device Loss
e. Storage Profiles, Clusters and DRS
3. Fiber Channel Security
Chapter 7 – Third Party Mitigation Solutions
2. Cisco Adaptive Security Virtual Appliance
3. Firefly Host – Juniper Networks Product
5. Sophos Endpoint Antivirus – Cloud
7. TrendMicro Deep Security
Chapter 8 – Assessing and Remediating
1. Assessment Program Objectives
2. Assessment Program Scope
3. Prerequisites and Reliance
4. Assessment Skills Requirement
Chapter 9 – Hardening the Virtual Machines
2. Making best use of Templates
6. Preventing Known Risks
Chapter 10 – Hardening the Host
4. Managing Access to Host
5. Firewall Best Practices
Chapter 11 – Hardening vCenter
6. Using the App Firewall
Appendix – Additional Products only covered in extended hour’s delivery (Bootcamp Format)
1. vCloud Native Controls
a. How vCloud functions with vSphere
c. Tenant and Landlord Controls
2. Compliance and vCenter Configuration Manager
a. Overview of Compliance
b. How Configuration Manager Helps
d. Free Compliance Checking Tools
3. Additional vCloud Networking Deep Dive